CVE-2025-56082
8.8Ruijie · RG-BCR and RG-BCR600W
A command injection vulnerability in Ruijie RG-BCR devices allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the check_changes endpoint.
Executive summary
A critical OS command injection vulnerability in Ruijie RG-BCR and RG-BCR600W devices allows authenticated remote attackers to achieve full system compromise.
Vulnerability
This vulnerability is an OS command injection flaw located within the check_changes function in the Lua controller file. It requires an authenticated user with low privileges to trigger the execution of arbitrary commands on the underlying operating system.
Business impact
The ability to execute arbitrary commands on network infrastructure equipment poses a severe risk to organizational security. Successful exploitation could lead to total system takeover, unauthorized access to internal network traffic, and potential persistence for lateral movement. The CVSS score of 8.8 reflects the high severity of this vulnerability, as it allows for complete confidentiality, integrity, and availability impact if exploited.
Remediation
Immediate Action: Contact Ruijie support or monitor the official vendor security portal to identify and apply the necessary firmware updates as soon as they become available.
Proactive Monitoring: Review administrative access logs for unusual POST requests directed at the check_changes endpoint or unexpected shell activity originating from the device.
Compensating Controls: Restrict management access to these devices to trusted administrative subnets and implement strict firewall rules to limit exposure of the management interface.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists as documented in the research repository hosted on GitHub.
Analyst recommendation
Given the capability for remote code execution on core network hardware, this vulnerability must be treated with high urgency. Administrators should prioritize identifying vulnerable devices within their environment and apply vendor-supplied patches immediately upon release to prevent potential exploitation of the command injection flaw.