CVE-2026-23699
7.2Ruijie Networks · AP180 series
The Ruijie Networks AP180 series contains an OS command injection vulnerability in firmware versions prior to AP_RGOS 11.9(4)B1P8, allowing for arbitrary command execution.
Executive summary
A critical OS command injection vulnerability in Ruijie Networks AP180 series access points permits authenticated attackers to execute arbitrary commands on the underlying system.
Vulnerability
This flaw is an OS command injection (CWE-78) occurring when the device fails to properly sanitize special elements in input. According to the CVSS vector, this vulnerability requires high privileges (PR:H) to trigger, meaning an authenticated administrator must initiate the malicious command.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve full system compromise, as it permits the execution of arbitrary commands with elevated privileges. Given the CVSS score of 7.2, this represents a high-severity risk that could lead to unauthorized network control, lateral movement, or the permanent disruption of wireless services within the organization.
Remediation
Immediate Action: Update all affected Ruijie Networks AP180 series access points to firmware version AP_RGOS 11.9(4)B1P8 or later immediately.
Proactive Monitoring: Review administrative access logs for unusual command execution patterns or unauthorized configuration changes on management interfaces.
Compensating Controls: Restrict access to the management interface of the access points to trusted administrative IP addresses only to prevent unauthorized users from reaching the vulnerable endpoint.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
The presence of an OS command injection vulnerability in network infrastructure components poses a significant risk to organizational integrity. Administrators should prioritize the deployment of the firmware update AP_RGOS 11.9(4)B1P8 across all identified AP180 units to remediate this flaw and prevent potential exploitation of the command injection vector.