CVE-2025-56082

8.8

Ruijie · RG-BCR and RG-BCR600W

A command injection vulnerability in Ruijie RG-BCR devices allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the check_changes endpoint.

Executive summary

A critical OS command injection vulnerability in Ruijie RG-BCR and RG-BCR600W devices allows authenticated remote attackers to achieve full system compromise.

Vulnerability

This vulnerability is an OS command injection flaw located within the check_changes function in the Lua controller file. It requires an authenticated user with low privileges to trigger the execution of arbitrary commands on the underlying operating system.

Business impact

The ability to execute arbitrary commands on network infrastructure equipment poses a severe risk to organizational security. Successful exploitation could lead to total system takeover, unauthorized access to internal network traffic, and potential persistence for lateral movement. The CVSS score of 8.8 reflects the high severity of this vulnerability, as it allows for complete confidentiality, integrity, and availability impact if exploited.

Remediation

Immediate Action: Contact Ruijie support or monitor the official vendor security portal to identify and apply the necessary firmware updates as soon as they become available.

Proactive Monitoring: Review administrative access logs for unusual POST requests directed at the check_changes endpoint or unexpected shell activity originating from the device.

Compensating Controls: Restrict management access to these devices to trusted administrative subnets and implement strict firewall rules to limit exposure of the management interface.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists as documented in the research repository hosted on GitHub.

Analyst recommendation

Given the capability for remote code execution on core network hardware, this vulnerability must be treated with high urgency. Administrators should prioritize identifying vulnerable devices within their environment and apply vendor-supplied patches immediately upon release to prevent potential exploitation of the command injection flaw.

More Ruijie CVEs

Sources