CVE-2025-56085

8.8

Ruijie · RG-EW1200

A command injection vulnerability in Ruijie RG-EW1200 allows authenticated attackers to execute arbitrary system commands via the module_set parameter in the config_retain.lua file.

Executive summary

An OS command injection vulnerability in Ruijie RG-EW1200 devices allows authenticated attackers to gain full system control, posing a significant risk to network integrity.

Vulnerability

This is an OS command injection flaw located in the /usr/local/lua/dev_config/config_retain.lua script. By sending a crafted POST request to the module_set endpoint, an authenticated attacker can execute arbitrary commands on the underlying operating system.

Business impact

The ability to execute arbitrary commands on network infrastructure equipment can lead to a complete compromise of the device. Given the CVSS score of 8.8, this vulnerability represents a high severity risk that could result in unauthorized lateral movement, data exfiltration, or the establishment of persistent backdoors within the network environment.

Remediation

Immediate Action: Contact the vendor immediately to obtain firmware updates that address this injection vulnerability, as no public patch is currently confirmed.

Proactive Monitoring: Monitor device traffic and system logs for suspicious POST requests targeting the config_retain.lua path or unusual shell execution patterns.

Compensating Controls: Implement strict network access control lists to limit management interface access to trusted administrative IP addresses only, reducing the attack surface for potential exploitation.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the researcher's technical write-up on GitHub.

Analyst recommendation

The high severity of this command injection vulnerability necessitates prompt attention from network administrators. Until a vendor-supplied firmware update is verified and applied, isolate affected RG-EW1200 devices from public-facing networks and restrict administrative access to the management interface to prevent unauthorized exploitation by authenticated users.

More Ruijie CVEs

Sources