CVE-2025-65363: Command Injection
Authenticated append-style command-injection Ruijie APs (APRGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the webaction.do endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65363?
CVE-2025-65363 is classified with high severity due to the potential for authenticated command injection leading to serious security consequences.
How do I fix CVE-2025-65363?
To remediate CVE-2025-65363, it's recommended to update to a patched version of Ruijie AP_RGOS that addresses this command injection vulnerability.
What vulnerabilities does CVE-2025-65363 introduce?
CVE-2025-65363 introduces risks such as file disclosure, device disruption, and potential network pivoting due to command injection capabilities.
Who is affected by CVE-2025-65363?
CVE-2025-65363 affects authenticated users of Ruijie AP_RGOS versions 11.1.x, who can exploit the vulnerability via the web_action.do endpoint.
What type of attack is CVE-2025-65363 associated with?
CVE-2025-65363 is associated with authenticated append-style command injection attacks that allow root shell execution.