CVE-2025-56752: Critical severity Ruijie RG-ES series switch firmware vulnerability
A vulnerability in the Ruijie RG-ES series switch firmware ESW1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56752?
CVE-2025-56752 is a critical vulnerability that allows remote attackers to bypass authentication mechanisms.
How do I fix CVE-2025-56752?
To fix CVE-2025-56752, update the Ruijie RG-ES series switch firmware to the latest version that addresses this vulnerability.
What devices are affected by CVE-2025-56752?
CVE-2025-56752 affects the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39.
Can CVE-2025-56752 lead to device control?
Yes, CVE-2025-56752 can allow attackers to gain unrestricted access and potentially seize control of affected devices.
How does CVE-2025-56752 exploit the vulnerability?
CVE-2025-56752 is exploited through crafted HTTP POST requests to the affected device, bypassing authentication.