CVE-2025-56096

8.8

Ruijie · RG-BCR and RG-BCR600W

An OS command injection vulnerability in Ruijie RG-BCR and RG-BCR600W allows authenticated attackers to execute arbitrary system commands via a crafted POST request.

Executive summary

A critical OS command injection flaw in Ruijie networking hardware poses a significant risk of full system compromise for affected devices.

Vulnerability

The vulnerability exists within the restart_modules function located in /usr/lib/lua/luci/controller/admin/common.lua, where improper input sanitization allows an authenticated attacker to inject and execute arbitrary OS commands.

Business impact

The CVSS score of 8.8 indicates a high severity risk that could lead to unauthorized system access, data exfiltration, or complete loss of device control. Successful exploitation allows an attacker to gain a foothold on the network perimeter, potentially facilitating lateral movement and severe disruption to business operations.

Remediation

Immediate Action: Contact Ruijie support or monitor the official vendor website to obtain and apply the latest security firmware update addressing this command injection flaw.

Proactive Monitoring: Review system access logs for unusual POST requests directed at the /usr/lib/lua/luci/controller/admin/common.lua endpoint, particularly those originating from unauthorized or suspicious administrative accounts.

Compensating Controls: Implement strict firewall rules to restrict access to the web management interface to only trusted administrative IP addresses, thereby reducing the attack surface for this authenticated vulnerability.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists as documented in the research write-up referenced by the CVE record.

Analyst recommendation

Given the high CVSS severity and the availability of technical documentation regarding the exploit, administrators should treat this vulnerability with high urgency. Restrict management interface access immediately and prioritize the deployment of vendor-supplied patches as soon as they become available to prevent potential unauthorized system-level command execution.

More Ruijie CVEs

Sources