Ruijie M18 OS Command Injection Vulnerability
Vulnerability
An OS command injection vulnerability exists in the Ruijie M18 EW_3.0(1)B11P226_M18_10223116 version. This vulnerability allows attackers to execute arbitrary commands by sending a crafted POST request to the module_set, targeting the /usr/local/lua/dev_config/config_retain.lua file.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
Added: Dec 11, 2025, 7:26 PM
Updated: Dec 11, 2025, 7:26 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
7.4remediation
0.0relevance
1.4threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
