Ruijie RG-BCR OS Command Injection Vulnerability
Vulnerability
A command injection vulnerability has been identified in the Ruijie RG-BCR600W model. This vulnerability allows authenticated remote attackers to execute arbitrary commands on the device. The issue arises in the Lua service handling POST requests to the 'restart_modules' endpoint, located in '/usr/lib/lua/luci/controller/admin/common.lua'.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
Reproduction
To reproduce this vulnerability, send a crafted POST request to the 'restart_modules' endpoint on a Ruijie RG-BCR600W device. The request must be designed to inject malicious commands that the server will execute.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
