ZeroHour

CVE-2026-92397

moderate

OS Command Injection in Ruijie RG-EW3000GX Router (configChange cc_set)

CVSS 4.0
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92397 is an operating system command injection vulnerability in the cc_set function of unifyframe-sgi.elf, part of the configChange component of the Ruijie RG-EW3000GX wireless router running firmware EW_3.0(1)B11P380. An attacker sends a crafted request in which the data.url argument is concatenated into a shell command without sanitization, allowing arbitrary OS commands to be executed remotely; per the CVSS 4.0 vector (PR:H), the attack requires an authenticated high-privilege (administrator-level) session but no user interaction. Successful exploitation yields full command execution on the device (confidentiality, integrity and availability impacts all rated High), enabling router takeover, traffic manipulation, and pivoting into the connected LAN. Only RG-EW3000GX units running the affected EW_3.0(1)B11P380 firmware are implicated, a product line typically deployed in SOHO and small-business Wi-Fi networks. The flaw is not listed in CISA KEV and no standalone public PoC has been catalogued, although the source advisory states an exploit has been publicly disclosed; no confirmed in-the-wild exploitation is documented.

What to do: Check the router's firmware version in the admin console and, if it is EW_3.0(1)B11P380, apply the latest EW 3.0 firmware from Ruijie's official support channel (no fixed version is specified in the available data, so confirm the patched release with the vendor). Minimize exposure by disabling remote/WAN management, restricting the management interface to trusted networks, and placing the device behind a firewall where possible. Monitor for unexpected requests to the configChange/unifyframe-sgi.elf handler containing shell metacharacters in the data.url parameter, and rotate administrator credentials on any device that may have been accessed.

Affected
Ruijie Networks RG-EW3000GX wireless routerEW_3.0(1)B11P380 (other firmware versions not confirmed in the available data)
Estimated exposure
moderateroughly 1,000-10,000 devices (a model/firmware-specific subset of the ~54,000 internet-exposed Ruijie Reyee routers found in public scans) — Public internet-wide scan research (Censys data cited in Wiz's 2023 Reyee analysis) identified on the order of 54,000 exposed Ruijie Reyee routers across the line; the RG-EW3000GX on one specific firmware build is a small fraction of that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.