Sploitus Remote OS Command Injection Vulnerabilities in Ruijie RG-EW3000GX
Article Content
Browse articles
- •Two critical vulnerabilities identified in Ruijie RG-EW3000GX.
- •Both vulnerabilities allow remote OS command injection.
- •Exploits for these vulnerabilities have been publicly disclosed.
Two vulnerabilities have been identified in the Ruijie RG-EW3000GX EW_3.0(1)B11P380 model. The first, CVE-2026-92398, affects the user_list_note module, allowing remote OS command injection via the Name argument in /etc/rg_config/admin. The second, CVE-2026-92397, involves the cc_set function in unifyframe-sgi.elf, enabling OS command injection through the data.url argument. Both vulnerabilities can be exploited remotely and have been made public, posing a significant risk to users of this device. Immediate action is advised for affected organizations to mitigate potential attacks.
Ask AI about this cluster
Answers cite the sources they use
Updated 4h ago How this analysis works
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…