CVE-2025-68459

7.2

Ruijie Networks Co., Ltd. · AP180 series Wireless AP

The Ruijie Networks AP180 series wireless access points contain an OS command injection vulnerability allowing authenticated attackers to execute arbitrary system commands via the CLI service.

Executive summary

An OS command injection vulnerability in Ruijie Networks AP180 series access points poses a critical risk by allowing authenticated attackers to execute arbitrary commands on the underlying operating system.

Vulnerability

This flaw is an OS command injection (CWE-78) vulnerability triggered via the command line interface. It requires the attacker to have high-level administrative access to the CLI service to inject and execute arbitrary system commands.

Business impact

Successful exploitation allows an attacker to gain full control over the affected wireless access point, potentially leading to unauthorized network configuration changes or the use of the device as a pivot point for internal network attacks. With a CVSS score of 7.2, this vulnerability represents a significant risk to organizational network integrity and operational availability.

Remediation

Immediate Action: Administrators should immediately update affected AP180 devices to a firmware version later than AP_RGOS 11.9(4)B1P8 as prescribed by the vendor advisory.

Proactive Monitoring: Monitor CLI access logs for unusual or unauthorized command strings and audit administrative user activity for suspicious behavior.

Compensating Controls: Restrict access to the device CLI to authorized management IP addresses only and enforce strong, unique credentials for all administrative accounts to limit the potential for unauthorized privilege escalation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for full system compromise, organizations currently utilizing the Ruijie AP180 series must treat this update with high priority. Ensure that all administrative access is strictly controlled and that devices are patched to the latest version to eliminate the command injection vector entirely.

More Ruijie Networks Co., Ltd. CVEs

Sources