CVE-2025-56130
8.8Ruijie · RG-S1930 S1930SWITCH_3
A command injection vulnerability in the Ruijie RG-S1930 switch allows authenticated attackers to execute arbitrary system commands via a crafted POST request to the module_update component.
Executive summary
An OS command injection vulnerability in Ruijie RG-S1930 switches allows an authenticated attacker to achieve full remote code execution, posing a high risk to network infrastructure.
Vulnerability
This is an OS command injection vulnerability (CWE-78) located in the /usr/local/lua/dev_config/ace_sw.lua file. It can be triggered by an authenticated attacker sending a malicious POST request to the module_update parameter.
Business impact
The ability to execute arbitrary system commands provides an attacker with complete control over the affected network switch. This risk is classified as High with a CVSS score of 8.8, as it facilitates unauthorized access to internal network traffic, potential lateral movement, and complete denial of service for managed segments.
Remediation
Immediate Action: Contact Ruijie support immediately to obtain the latest firmware update or security patch for version 3.0(1)B11P230.
Proactive Monitoring: Review system access logs for anomalous POST requests directed at the module_update endpoint or unexpected execution of shell commands.
Compensating Controls: Implement strict access control lists to limit management interface access to trusted administrative IP addresses only, which reduces the likelihood of exploitation by unauthorized users.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the researcher's write-up on GitHub.
Analyst recommendation
Given the high CVSS score and the existence of a public exploit, this vulnerability should be treated as a priority item for all network administrators. Organizations should verify their firmware versions immediately and restrict access to the device management plane until a verified patch can be applied.