Ruijie Networks OS Command Injection Vulnerability in Multiple Products

Vulnerability

A command injection vulnerability has been identified in several Ruijie Networks products, including the RG-YST, RG-EST310 V2, RG-EST350 V2, RG-EW300 PRO, and specific AP models. This vulnerability allows authenticated remote attackers to execute arbitrary commands on the affected device. The issue arises in the Lua service 'pwdmodify', where crafted POST requests can be used to inject and execute commands on the operating system.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send a POST request to the 'pwdmodify' endpoint in the 'common.lua' module. The request must be crafted to include the desired command injection payload. This can be done using tools like curl or Postman, or through a custom script that automates the process.

Added: Dec 11, 2025, 7:48 PM
Updated: Dec 11, 2025, 7:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.