CVE-2025-56087

8.8

Ruijie · RG-BCR and RG-BCR600W

A command injection vulnerability in Ruijie network devices allows authenticated attackers to execute arbitrary system commands via a malicious POST request to the tcpdump utility.

Executive summary

An OS command injection vulnerability in Ruijie RG-BCR and RG-BCR600W devices poses a high risk of total system compromise for organizations using the affected hardware.

Vulnerability

The vulnerability is an OS command injection flaw located in the run_tcpdump function within the Lua controller files. An attacker with low privileges (authenticated user) can inject arbitrary system commands into the device through a crafted POST request.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands with the privileges of the web service, which typically results in full system control. Given the CVSS score of 8.8, this represents a high-severity threat that could lead to complete data exfiltration, service disruption, or the use of the device as a pivot point for further lateral movement within the internal network.

Remediation

Immediate Action: Contact Ruijie support or monitor the official vendor security portal to identify and apply the necessary firmware updates or patches as soon as they are made available.

Proactive Monitoring: Review device access logs for suspicious POST requests targeting the common_tcpdump file or unusual execution patterns originating from authenticated user accounts.

Compensating Controls: Restrict management interface access to trusted administrative IP addresses and employ a Web Application Firewall (WAF) to inspect and block anomalous traffic patterns attempting to access the vulnerable Lua controller.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists as documented in the security researcher's report on GitHub.

Analyst recommendation

This vulnerability presents a significant security risk due to the potential for remote command execution on critical network infrastructure. Security teams should prioritize identifying affected devices in their environment and maintain a state of high alert until a vendor-supplied patch is applied. Immediate implementation of network-level access controls is strongly recommended to minimize the attack surface.

More Ruijie CVEs

Sources