CVE-2025-56129

8.8

Ruijie · RG-BCR860

An OS command injection vulnerability in Ruijie RG-BCR860 devices allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the action_diagnosis endpoint.

Executive summary

A critical OS command injection vulnerability in Ruijie RG-BCR860 devices allows authenticated attackers to achieve remote code execution on affected hardware.

Vulnerability

This vulnerability is an OS command injection flaw located in the action_diagnosis function of the LuCI controller. It requires the attacker to possess low-level privileges to successfully submit the malicious POST request.

Business impact

The ability to execute arbitrary OS commands on network appliances poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized access to sensitive network traffic, or the deployment of persistent backdoors, justifying the high CVSS score of 8.8.

Remediation

Immediate Action: Contact the vendor immediately to obtain the latest firmware updates or security patches for the RG-BCR860 series.

Proactive Monitoring: Inspect system and web application logs for suspicious POST requests directed at the action_diagnosis endpoint, particularly those containing shell metacharacters.

Compensating Controls: Implement strict network access controls to limit management interface access to authorized administrative IP addresses only, reducing the attack surface for potential exploits.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists via the researcher's published technical documentation on GitHub.

Analyst recommendation

Given the potential for complete system takeover, administrators must prioritize the identification of all vulnerable Ruijie appliances within their environment. Apply all available security updates immediately to remediate the command injection flaw and minimize the risk of unauthorized remote code execution.

More Ruijie CVEs

Sources