Ruijie Rg-Ew300 Pro Firmware vulnerabilities
6 known vulnerabilities affecting ruijie/rg-ew300_pro_firmware.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6
Vulnerabilities
Page 1 of 1
CVE-2025-56094P2HIGHCVSS 8.8v3.0\(1\)b11p2192025-12-11
CVE-2025-56094 [HIGH] CWE-78 CVE-2025-56094: OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execu
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/host_access_delay.lua.
nvd
CVE-2025-56085P2HIGHCVSS 8.8v3.0\(1\)b11p2192025-12-11
CVE-2025-56085 [HIGH] CWE-78 CVE-2025-56085: OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.
nvd
CVE-2025-56098P2HIGHCVSS 8.8v3.0\(1\)b11p2192025-12-11
CVE-2025-56098 [HIGH] CWE-78 CVE-2025-56098: OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execu
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.
nvd
CVE-2025-56093P2HIGHCVSS 8.8v3.0\(1\)b11p2192025-12-11
CVE-2025-56093 [HIGH] CWE-78 CVE-2025-56093: OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execu
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua.
nvd
CVE-2025-56108P2HIGHCVSS 8.8v3.0\(1\)b11p2192025-12-11
CVE-2025-56108 [HIGH] CWE-78 CVE-2025-56108: OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execu
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.
nvd
CVE-2023-38902P2HIGHCVSS 8.8v3.0\(1\)b11p2192023-08-17
CVE-2023-38902 [HIGH] CWE-77 CVE-2023-38902: A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-
A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attac
nvd