Aggregates CVE and security vulnerability intelligence across all Ruijie Networks-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk cross-site scripting and vendor risk path handling and related security problems, affecting vendor surface production workloads and vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-56130 | OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST request to the module_update in file /usr/local/lua/dev_config/ace_sw.lua. | [email protected] | 8.8 | 1.08% | 2025-12-11 | 2025-12-31 |
| CVE-2025-56129 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis.lua. | [email protected] | 8.8 | 1.44% | 2025-12-11 | 2025-12-15 |
| CVE-2025-56127 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_wanobj in file /usr/lib/lua/luci/controller/admin/common.lua. | [email protected] | 8.8 | 1.71% | 2025-12-11 | 2025-12-18 |
| CVE-2025-56124 | OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | [email protected] | 7.8 | 0.18% | 2025-12-11 | 2025-12-18 |
| CVE-2025-56123 | OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | [email protected] | 8.8 | 0.92% | 2025-12-11 | 2026-01-27 |
| CVE-2025-56122 | OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | [email protected] | 8.8 | 0.68% | 2025-12-11 | 2025-12-23 |
| CVE-2025-56120 | OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua. | [email protected] | 8.8 | 0.68% | 2025-12-11 | 2025-12-23 |
| CVE-2025-56118 | OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | [email protected] | 8.8 | 0.68% | 2025-12-11 | 2025-12-23 |
| CVE-2025-56117 | OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | [email protected] | 8.8 | 1.71% | 2025-12-11 | 2026-01-07 |
| CVE-2025-56114 | OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua. | [email protected] | 8.8 | 0.92% | 2025-12-11 | 2026-01-07 |
| CVE-2025-56113 | OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua. | [email protected] | 8.8 | 0.19% | 2025-12-11 | 2026-02-11 |
| CVE-2025-56111 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the network_set_wan_conf in file /usr/lib/lua/luci/controller/admin/netport.lua. | [email protected] | 8.8 | 1.71% | 2025-12-11 | 2026-01-07 |
| CVE-2025-56110 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_deal_update in file /usr/lib/lua/luci/controller/api/rcmsAPI.lua. | [email protected] | 8.8 | 1.09% | 2025-12-11 | 2026-01-26 |
| CVE-2025-56109 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_wireless in file /usr/lib/lua/luci/control/admin/wireless.lua. | [email protected] | 8.8 | 1.09% | 2025-12-11 | 2026-01-26 |
| CVE-2025-56108 | OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua. | [email protected] | 8.8 | 0.31% | 2025-12-11 | 2026-01-26 |
| CVE-2025-56107 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua. | [email protected] | 8.8 | 0.12% | 2025-12-11 | 2025-12-26 |
| CVE-2025-56106 | OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | [email protected] | 8.8 | 0.17% | 2025-12-11 | 2026-01-26 |
| CVE-2025-56102 | OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | [email protected] | 8.8 | 0.68% | 2025-12-11 | 2026-01-27 |
| CVE-2025-56101 | OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | [email protected] | 8.8 | 0.22% | 2025-12-11 | 2026-01-27 |
| CVE-2025-56099 | OS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua. | [email protected] | 8.8 | 0.19% | 2025-12-11 | 2026-02-11 |