CVE-2026-92398
largeAuthenticated OS Command Injection in Ruijie RG-EW3000GX Router Firmware
The Ruijie RG-EW3000GX Wi-Fi router running firmware EW_3.0(1)B11P380 contains an OS command injection flaw (CWE-77/CWE-78) in the user_list_note module, which handles the file /etc/rg_config/admin. A remote attacker who already holds administrative privileges manipulates the 'Name' argument, causing injected commands to be executed on the router's operating system; the CVSS 4.0 vector (PR:H) confirms admin-level access is required, so this is not an unauthenticated bug. Successful exploitation yields full command execution on the device, with confidentiality, integrity and availability impacts rated high for both the router and subsequent (downstream) systems, effectively letting an attacker take over the gateway and pivot into the network behind it. Only the RG-EW3000GX on build EW_3.0(1)B11P380 is confirmed affected; other firmware builds or EW-series models are not ruled out but are not documented in the advisory. The advisory states the exploit has been made public and could be used, though no standalone PoC is catalogued in this listing and the flaw is not yet in CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade the RG-EW3000GX to a firmware release newer than EW_3.0(1)B11P380 as soon as Ruijie publishes a fix (no fixed version is named in the advisory); until then, disable WAN-side/remote administration and restrict the management interface to trusted LAN clients or management allowlists. Rotate administrative credentials and audit the admin/user list configuration (the user_list_note module and /etc/rg_config/admin data) for unauthorized accounts, since that is the component under attack. Because exploitation requires admin-level privileges, exposed management ports combined with weak or reused passwords are the main risk multipliers — prioritize internet-reachable devices.
| Ruijie Networks RG-EW3000GX router | EW_3.0(1)B11P380 (only build named in the advisory; fixed version not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.