CVE-2025-56088 | Ruijie RG-BCR RG-BCR860 POST service.lua action_service os command injection
A vulnerability categorized as critical has been discovered in Ruijie RG-BCR RG-BCR860. This affects the function action_service in the library /usr/lib/lua/luci/controller/admin/service.lua of the component POST Handler. Such manipulation leads to os command injection.
This vulnerability is listed as CVE-2025-56088. The attack may be performed from remote. There is no available exploit.