CVE-2025-56095
8.8Ruijie · RG-EW1200G PRO
An OS command injection vulnerability in the Ruijie RG-EW1200G PRO allows authenticated attackers to execute arbitrary system commands via a crafted POST request.
Executive summary
An OS command injection vulnerability in Ruijie RG-EW1200G PRO routers allows authenticated attackers to achieve full system compromise via malicious POST requests.
Vulnerability
The flaw exists in the module_set function within the /usr/local/lua/dev_sta/nbr_cwmp.lua file, where insufficient input sanitization allows an authenticated user to inject arbitrary system commands.
Business impact
Successful exploitation of this vulnerability leads to full control over the affected networking hardware. Given the CVSS score of 8.8, this represents a high-severity risk that could result in total system compromise, unauthorized network traffic interception, or the use of the device as a pivot point for further attacks against the internal network.
Remediation
Immediate Action: Contact Ruijie support or monitor the official vendor portal for firmware updates addressing this command injection flaw.
Proactive Monitoring: Review device access logs for unusual POST requests targeting the /usr/local/lua/dev_sta/nbr_cwmp.lua endpoint or unexpected system process spawning.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only and disable remote management features if they are not strictly required for operations.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research write-up hosted on GitHub.
Analyst recommendation
Organizations utilizing the affected Ruijie RG-EW1200G PRO hardware must treat this vulnerability with high priority. While an official patch status is currently unknown, administrators should immediately limit management interface exposure and remain vigilant for vendor-supplied firmware updates to remediate the underlying command injection vector.