CVE-2025-56123: Command Injection
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleget in file /usr/local/lua/devsta/networkConnect.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56123?
CVE-2025-56123 has a high severity rating due to its potential to allow remote command execution by attackers.
How do I fix CVE-2025-56123?
To remediate CVE-2025-56123, users should upgrade to the latest version of the Ruijie RG-EW1200G PRO firmware that addresses this vulnerability.
What systems are affected by CVE-2025-56123?
CVE-2025-56123 affects Ruijie RG-EW1200G PRO versions V1.00 to V4.00.
How can an attacker exploit CVE-2025-56123?
An attacker can exploit CVE-2025-56123 by sending a crafted POST request to the module_get endpoint in the networkConnect.lua file.
What precautions should I take regarding CVE-2025-56123?
Users should implement network security measures and regularly monitor for unusual activity while ensuring devices are updated to mitigate CVE-2025-56123.