CVE-2025-56118

8.8

Ruijie · X60 PRO

A command injection vulnerability in the Ruijie X60 PRO router allows authenticated attackers to execute arbitrary system commands via a crafted POST request to a specific Lua module.

Executive summary

An OS command injection vulnerability in the Ruijie X60 PRO allows authenticated attackers to achieve remote code execution on affected hardware.

Vulnerability

The vulnerability exists within the nbr_cwmp.lua file, where the module_set function fails to properly sanitize input. An attacker with low-level privileges can leverage this flaw to execute arbitrary system commands via a crafted POST request.

Business impact

This vulnerability carries a CVSS score of 8.8, reflecting its high severity. Successful exploitation allows an attacker to gain full control over the network device, which may lead to unauthorized network access, data interception, or the use of the router as a pivot point for further lateral movement within the corporate environment.

Remediation

Immediate Action: Since a specific patch version is currently unknown, users should restrict access to the web management interface to trusted management networks only and monitor vendor channels for firmware updates.

Proactive Monitoring: Security teams should monitor device logs for suspicious POST requests targeting the /usr/local/lua/dev_sta/nbr_cwmp.lua endpoint or unusual shell activity originating from the device.

Compensating Controls: Implement strict firewall rules to block unauthorized access to the web management interface from external or untrusted network segments.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the vulnerability report provided on GitHub.

Analyst recommendation

Given the severity of this command injection flaw, organizations should prioritize isolating the affected Ruijie X60 PRO devices from internet-facing segments. Administrators must verify if their firmware version is vulnerable and apply official security updates as soon as they are made available by the vendor to prevent potential system compromise.

More Ruijie CVEs

Sources