CVE-2025-56085
8.8Ruijie · RG-EW1200
A command injection vulnerability in Ruijie RG-EW1200 allows authenticated attackers to execute arbitrary system commands via the module_set parameter in the config_retain.lua file.
Executive summary
An OS command injection vulnerability in Ruijie RG-EW1200 devices allows authenticated attackers to gain full system control, posing a significant risk to network integrity.
Vulnerability
This is an OS command injection flaw located in the /usr/local/lua/dev_config/config_retain.lua script. By sending a crafted POST request to the module_set endpoint, an authenticated attacker can execute arbitrary commands on the underlying operating system.
Business impact
The ability to execute arbitrary commands on network infrastructure equipment can lead to a complete compromise of the device. Given the CVSS score of 8.8, this vulnerability represents a high severity risk that could result in unauthorized lateral movement, data exfiltration, or the establishment of persistent backdoors within the network environment.
Remediation
Immediate Action: Contact the vendor immediately to obtain firmware updates that address this injection vulnerability, as no public patch is currently confirmed.
Proactive Monitoring: Monitor device traffic and system logs for suspicious POST requests targeting the config_retain.lua path or unusual shell execution patterns.
Compensating Controls: Implement strict network access control lists to limit management interface access to trusted administrative IP addresses only, reducing the attack surface for potential exploitation.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the researcher's technical write-up on GitHub.
Analyst recommendation
The high severity of this command injection vulnerability necessitates prompt attention from network administrators. Until a vendor-supplied firmware update is verified and applied, isolate affected RG-EW1200 devices from public-facing networks and restrict administrative access to the management interface to prevent unauthorized exploitation by authenticated users.