Executive brief
Ruijie RG-EW3000GX is a wireless access point used to provide network connectivity in enterprise environments. A remote attacker can inject arbitrary operating system commands through the configChange function, allowing complete compromise of the device and potential lateral movement into the network.
Technical details
The vulnerability exists in the cc_set function of the unifyframe-sgi.elf component in Ruijie RG-EW3000GX firmware EW_3.0(1)B11P380. The configChange functionality fails to properly validate the data.url argument before passing it to an OS command execution context, allowing OS command injection. The attack is remotely exploitable without authentication. An attacker can execute arbitrary commands with device privileges, leading to complete device compromise, data theft, or use as a pivot point for network attacks.
Affected products
- Ruijie RG-EW3000GX EW_3.0(1)B11P380
Timeline
- 2026-09-16: disclosed