CVE-2025-9424: Ruijie WS7204-A branch_import.php os command injection
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itboxpi/branchimport.php?a=branchlist. Such manipulation of the argument province leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9424?
CVE-2025-9424 is classified as a high-severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-9424?
To mitigate CVE-2025-9424, it is recommended to update the Ruijie WS7204-A firmware to the latest version provided by the vendor.
What type of vulnerability is CVE-2025-9424?
CVE-2025-9424 is an OS command injection vulnerability found in the branch_import.php file.
Who is affected by CVE-2025-9424?
The vulnerability affects users of the Ruijie WS7204-A device version released on June 15, 2017.
What could an attacker do with CVE-2025-9424?
An attacker exploiting CVE-2025-9424 could execute arbitrary OS commands on the affected device remotely.