CVE-2025-56077
8.8Ruijie · RG-RAP2200(E)
A command injection vulnerability in the Ruijie RG-RAP2200(E) allows authenticated attackers to execute arbitrary system commands via a crafted POST request.
Executive summary
An OS command injection vulnerability in the Ruijie RG-RAP2200(E) series allows authenticated attackers to execute arbitrary system commands, posing a significant risk of full system compromise.
Vulnerability
This vulnerability is an OS command injection flaw located in the module_set function within the file /usr/local/lua/dev_sta/nbr_cwmp.lua. According to the CVSS vector (PR:L), the attack requires a low level of authentication to trigger.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected device, potentially leading to a complete loss of confidentiality, integrity, and availability. With a CVSS score of 8.8, this flaw represents a high-severity risk that could lead to unauthorized network access or the use of compromised devices as pivot points within the internal infrastructure.
Remediation
Immediate Action: Contact Ruijie support or monitor the official vendor security portal for the release of a firmware update that patches the vulnerable module.
Proactive Monitoring: Review web server access logs for suspicious POST requests directed at the /usr/local/lua/dev_sta/nbr_cwmp.lua endpoint.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and implement a Web Application Firewall (WAF) to filter malicious POST payloads.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists as documented in the research report linked via the GitHub reference provided in the CVE record.
Analyst recommendation
Given the high CVSS score and the presence of public technical details, organizations using the Ruijie RG-RAP2200(E) should prioritize this vulnerability. Administrators must verify their current firmware versions and apply the vendor-provided patch as soon as it becomes available to prevent potential remote command execution.