Ruijie M18 OS Command Injection Vulnerability

Vulnerability

An OS command injection vulnerability exists in the Ruijie M18 EW_3.0(1)B11P226_M18_10223116 version. This vulnerability allows attackers to execute arbitrary commands by sending a crafted POST request to the module_set, targeting the /usr/local/lua/dev_config/config_retain.lua file.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Added: Dec 11, 2025, 7:26 PM
Updated: Dec 11, 2025, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.