CVE-2025-56113

8.8

Ruijie · RG-YST EST, YSTAP_3

A command injection vulnerability in Ruijie RG-YST EST and YSTAP_3 allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the pwdmodify endpoint.

Executive summary

An OS command injection vulnerability in Ruijie RG-YST EST and YSTAP_3 devices poses a critical risk by allowing authenticated attackers to execute arbitrary commands with high system privileges.

Vulnerability

The vulnerability is an OS command injection flaw located in the pwdmodify function within the /usr/lib/lua/luci/modules/common.lua file. It requires the attacker to have low-level privileges to successfully submit the crafted POST request.

Business impact

The ability to execute arbitrary OS commands on network infrastructure devices can lead to total system compromise, including unauthorized data access, network interception, and complete loss of device control. Given the CVSS score of 8.8, this vulnerability is classified as High severity, representing a significant risk to the integrity and availability of the affected network environment.

Remediation

Immediate Action: Contact the vendor or consult the official Ruijie security portal to obtain firmware updates that address this command injection vulnerability.

Proactive Monitoring: Review system access logs for suspicious POST requests targeting the pwdmodify endpoint, particularly those containing shell metacharacters or unexpected command strings.

Compensating Controls: Implement strict network access control lists to restrict management interface access to authorized administrative IP addresses only, effectively reducing the attack surface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists via the technical write-up referenced in the CVE record.

Analyst recommendation

The severity of this command injection vulnerability necessitates prompt action to secure affected Ruijie devices. Administrators should prioritize identifying and patching all vulnerable instances of RG-YST EST and YSTAP_3, as the existence of a public proof-of-concept increases the likelihood of exploitation attempts.

More Ruijie CVEs

Sources