CVE-2025-65363
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.
Affected (1)
Products: Ruijie: Rg Ap720 L Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.1.0 to 11.1\(9\)B1P21 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Ap720 L | All versions |
References (3)
Source: cve@mitre.org
Third Party Advisory
Timeline
No history available yet.