CVE-2025-56110

8.8

Ruijie · RG-BCR, RG-BCR860

A command injection vulnerability in Ruijie RG-BCR devices allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the rcmsAPI controller.

Executive summary

An OS command injection vulnerability in Ruijie RG-BCR series devices poses a high risk of total system compromise for organizations failing to restrict access to management interfaces.

Vulnerability

The vulnerability is an OS command injection flaw located within the action_deal_update function of the rcmsAPI controller (rcmsAPI.lua). Per the CVSS vector, this requires low privileges, meaning an authenticated user can leverage this flaw to execute arbitrary commands on the underlying operating system.

Business impact

The ability to execute arbitrary commands on network infrastructure equipment carries severe business consequences, including the potential for complete device takeover, lateral movement within the network, and data exfiltration. With a CVSS score of 8.8, this vulnerability represents a high-severity threat that could lead to significant operational downtime and a total loss of confidentiality, integrity, and availability for the affected segment.

Remediation

Immediate Action: Contact Ruijie support or monitor the official vendor security portal for firmware updates addressing this command injection flaw.

Proactive Monitoring: Review access logs for the /usr/lib/lua/luci/controller/api/rcmsAPI endpoint to identify anomalous POST requests or suspicious command patterns.

Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and employ a Web Application Firewall (WAF) to inspect and block malicious POST payloads targeting the API.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists as documented in the research write-up hosted on GitHub.

Analyst recommendation

Given the high CVSS score and the availability of public technical details, this vulnerability presents a significant risk to network security. IT administrators should prioritize identifying affected Ruijie devices within their environment and restrict management access immediately. Once the vendor releases a patch, it must be applied across all affected units without delay to prevent potential exploitation.

More Ruijie CVEs

Sources