Junglewise Threat Intelligence

CVE-2025-65363: Ruijie AP_RGOS command injection in web_action.do

CVE-2025-65363 · Severity: high · CVSS 7.2 · Published 2025-12-08

Executive brief

A vulnerability in Ruijie wireless access points allows an authorized administrator to execute unauthorized system commands. By sending specially crafted requests to the device's management interface, an attacker with valid login credentials can take full control of the device's operating system. This could lead to the theft of sensitive configuration files, disruption of wireless services, or use of the device as a jumping-off point to attack other parts of the corporate network.

Technical details

An authenticated command injection vulnerability exists in Ruijie APs running AP_RGOS 11.1.x. The flaw is located in the 'command' parameter of the 'web_action.do' endpoint, which fails to properly neutralize special elements used in shell expressions. An attacker with administrative web access can append shell commands that are subsequently executed with root privileges. This allows for full system compromise, including file disclosure and network pivoting. While the vendor reportedly addressed this issue internally in 2021, older firmware versions such as 11.1(9)B1P21 remain vulnerable.

Affected products

  • Ruijie AP_RGOS 11.1.x (specifically versions prior to 2021, including 11.1(9)B1P21)

Timeline

  • 2021: patched: Vendor reported internal fix (no CVE assigned at the time)
  • 2025-10-25: disclosed: Vulnerability rediscovered and reported to vendor
  • 2025-12-08: advisory: CVE assigned and public advisory published

References