CVE-2025-56113
8.8Ruijie · RG-YST EST, YSTAP_3
A command injection vulnerability in Ruijie RG-YST EST and YSTAP_3 allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the pwdmodify endpoint.
Executive summary
An OS command injection vulnerability in Ruijie RG-YST EST and YSTAP_3 devices poses a critical risk by allowing authenticated attackers to execute arbitrary commands with high system privileges.
Vulnerability
The vulnerability is an OS command injection flaw located in the pwdmodify function within the /usr/lib/lua/luci/modules/common.lua file. It requires the attacker to have low-level privileges to successfully submit the crafted POST request.
Business impact
The ability to execute arbitrary OS commands on network infrastructure devices can lead to total system compromise, including unauthorized data access, network interception, and complete loss of device control. Given the CVSS score of 8.8, this vulnerability is classified as High severity, representing a significant risk to the integrity and availability of the affected network environment.
Remediation
Immediate Action: Contact the vendor or consult the official Ruijie security portal to obtain firmware updates that address this command injection vulnerability.
Proactive Monitoring: Review system access logs for suspicious POST requests targeting the pwdmodify endpoint, particularly those containing shell metacharacters or unexpected command strings.
Compensating Controls: Implement strict network access control lists to restrict management interface access to authorized administrative IP addresses only, effectively reducing the attack surface.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists via the technical write-up referenced in the CVE record.
Analyst recommendation
The severity of this command injection vulnerability necessitates prompt action to secure affected Ruijie devices. Administrators should prioritize identifying and patching all vulnerable instances of RG-YST EST and YSTAP_3, as the existence of a public proof-of-concept increases the likelihood of exploitation attempts.