ZeroHour

CVE-2026-92398

large

Authenticated OS Command Injection in Ruijie RG-EW3000GX Router Firmware

CVSS 4.0
8.5 high
EPSS
Published
()
Modified
AI analysis

The Ruijie RG-EW3000GX Wi-Fi router running firmware EW_3.0(1)B11P380 contains an OS command injection flaw (CWE-77/CWE-78) in the user_list_note module, which handles the file /etc/rg_config/admin. A remote attacker who already holds administrative privileges manipulates the 'Name' argument, causing injected commands to be executed on the router's operating system; the CVSS 4.0 vector (PR:H) confirms admin-level access is required, so this is not an unauthenticated bug. Successful exploitation yields full command execution on the device, with confidentiality, integrity and availability impacts rated high for both the router and subsequent (downstream) systems, effectively letting an attacker take over the gateway and pivot into the network behind it. Only the RG-EW3000GX on build EW_3.0(1)B11P380 is confirmed affected; other firmware builds or EW-series models are not ruled out but are not documented in the advisory. The advisory states the exploit has been made public and could be used, though no standalone PoC is catalogued in this listing and the flaw is not yet in CISA's Known Exploited Vulnerabilities catalog.

What to do: Upgrade the RG-EW3000GX to a firmware release newer than EW_3.0(1)B11P380 as soon as Ruijie publishes a fix (no fixed version is named in the advisory); until then, disable WAN-side/remote administration and restrict the management interface to trusted LAN clients or management allowlists. Rotate administrative credentials and audit the admin/user list configuration (the user_list_note module and /etc/rg_config/admin data) for unauthorized accounts, since that is the component under attack. Because exploitation requires admin-level privileges, exposed management ports combined with weak or reused passwords are the main risk multipliers — prioritize internet-reachable devices.

Affected
Ruijie Networks RG-EW3000GX routerEW_3.0(1)B11P380 (only build named in the advisory; fixed version not specified)
Estimated exposure
large≈10,000–100,000 internet-exposed routers (estimated; total deployed base plausibly higher) — No public exposure counts exist for this model, so the estimate is based on deployment patterns: the RG-EW3000GX is a mass-market consumer/SOHO Wi-Fi 6 model from Ruijie, a leading Chinese networking vendor, whose SOHO router admin…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.