CVE-2025-56106 | Ruijie RG-EW1800GX POST nbr_cwmp.lua module_set os command injection
A vulnerability, which was classified as critical, has been found in Ruijie RG-EW1800GX. Affected by this issue is the function module_set of the file /usr/local/lua/dev_sta/nbr_cwmp.lua of the component POST Handler. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2025-56106. It is possible to initiate the attack remotely. There is no exploit available.