CVE-2025-56123

8.8

Ruijie · RG-EW1200G PRO

An OS command injection vulnerability exists in Ruijie RG-EW1200G PRO devices, allowing authenticated attackers to execute arbitrary system commands via a crafted POST request.

Executive summary

A critical OS command injection vulnerability in Ruijie RG-EW1200G PRO devices allows authenticated remote attackers to achieve full system compromise.

Vulnerability

This is an OS command injection flaw located in the module_get function within the file /usr/local/lua/dev_sta/networkConnect.lua, which can be triggered by an authenticated attacker via a crafted POST request.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting a high risk of total system compromise. Successful exploitation grants an attacker the ability to execute arbitrary commands with the privileges of the underlying service, potentially leading to unauthorized data access, network lateral movement, or complete device takeover.

Remediation

Immediate Action: Contact the vendor or monitor the official support portal for the release of a security patch, as no official fix has been confirmed at this time.

Proactive Monitoring: Inspect network traffic and device logs for suspicious POST requests targeting the /usr/local/lua/dev_sta/networkConnect.lua endpoint.

Compensating Controls: Restrict administrative access to the device management interface to trusted IP addresses only and disable remote management features if they are not strictly required for operations.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists as documented in the researcher's GitHub repository.

Analyst recommendation

Given the severity of command injection and the availability of technical details, administrators must prioritize the protection of these devices. Until a vendor patch is applied, limit exposure by isolating the management interface from the public internet or untrusted network segments to prevent exploitation by malicious actors.

More Ruijie CVEs

Sources