CVE-2025-56130

8.8

Ruijie · RG-S1930 S1930SWITCH_3

A command injection vulnerability in the Ruijie RG-S1930 switch allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the module_update component.

Executive summary

An OS command injection vulnerability in Ruijie RG-S1930 switches allows an authenticated attacker to achieve full remote code execution, posing a high risk to network infrastructure.

Vulnerability

This is an OS command injection vulnerability (CWE-78) located in the /usr/local/lua/dev_config/ace_sw.lua file. It can be triggered by an authenticated attacker sending a malicious POST request to the module_update parameter.

Business impact

The ability to execute arbitrary system commands provides an attacker with complete control over the affected network switch. This risk is classified as High with a CVSS score of 8.8, as it facilitates unauthorized access to internal network traffic, potential lateral movement, and complete denial of service for managed segments.

Remediation

Immediate Action: Contact Ruijie support immediately to obtain the latest firmware update or security patch for version 3.0(1)B11P230.

Proactive Monitoring: Review system access logs for anomalous POST requests directed at the module_update endpoint or unexpected execution of shell commands.

Compensating Controls: Implement strict access control lists to limit management interface access to trusted administrative IP addresses only, which reduces the likelihood of exploitation by unauthorized users.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the researcher's write-up on GitHub.

Analyst recommendation

Given the high CVSS score and the existence of a public exploit, this vulnerability should be treated as a priority item for all network administrators. Organizations should verify their firmware versions immediately and restrict access to the device management plane until a verified patch can be applied.

More Ruijie CVEs

Sources