CVE-2025-56098
8.8Ruijie · X30-PRO
A command injection vulnerability in Ruijie X30-PRO allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the networkConnect module.
Executive summary
An OS command injection vulnerability in the Ruijie X30-PRO router allows authenticated attackers to gain full system control through malicious network requests.
Vulnerability
This is an OS command injection vulnerability (CWE-78) occurring in the networkConnect lua script. The vulnerability can be triggered by an authenticated attacker sending a specially crafted POST request to the module_get endpoint.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity level. Successful exploitation allows for complete system compromise, enabling attackers to execute arbitrary code with elevated privileges, which can lead to unauthorized data access, network lateral movement, or complete device incapacitation.
Remediation
Immediate Action: Contact Ruijie support or monitor the official vendor portal for the release of a firmware update that patches the command injection flaw in the networkConnect module.
Proactive Monitoring: Review device access logs for unusual POST requests directed at the /usr/local/lua/dev_sta/networkConnect path.
Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses only, and employ a network firewall to block unauthorized traffic attempting to reach the management module.
Exploitation status
Public Exploit Available: Yes, a technical write-up detailing the attack vector and proof-of-concept is available via the researcher's GitHub repository.
Analyst recommendation
Given the potential for full system control, organizations currently using the affected Ruijie X30-PRO firmware should isolate the device from public-facing segments immediately. Ensure that administrative credentials are complex and rotated regularly while awaiting a vendor-supplied patch. Monitor for any signs of unauthorized configuration changes or anomalous traffic patterns originating from the management interface.