Total
6 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-56092 | 1 Ruijie | 4 Rg-ew300t, Rg-ew300t Firmware, X30 Pro and 1 more | 2026-01-29 | N/A | 8.8 HIGH |
| OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | |||||
| CVE-2025-56098 | 1 Ruijie | 4 Rg-ew300 Pro, Rg-ew300 Pro Firmware, X30 Pro and 1 more | 2026-01-27 | N/A | 8.8 HIGH |
| OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | |||||
| CVE-2025-56093 | 1 Ruijie | 6 Rg-eap602, Rg-eap602 Firmware, Rg-ew300 Pro and 3 more | 2026-01-27 | N/A | 8.8 HIGH |
| OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua. | |||||
| CVE-2025-56094 | 1 Ruijie | 4 Rg-ew300 Pro, Rg-ew300 Pro Firmware, X30 Pro and 1 more | 2026-01-27 | N/A | 8.8 HIGH |
| OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/host_access_delay.lua. | |||||
| CVE-2025-56108 | 1 Ruijie | 10 Rg-eap602, Rg-eap602 Firmware, Rg-est310 and 7 more | 2026-01-26 | N/A | 8.8 HIGH |
| OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua. | |||||
| CVE-2025-56117 | 1 Ruijie | 4 Rg-est310, Rg-est310 Firmware, X30 Pro and 1 more | 2026-01-07 | N/A | 8.8 HIGH |
| OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | |||||
