CVE-2026-92398 PUBLISHED

Ruijie RG-EW3000GX user_list_note admin os command injection

Assigner: VulDB
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
CVSS Score: 9.4

Product Status

Vendor Ruijie
Product RG-EW3000GX
Versions
  • Version EW_3.0(1)B11P380 is affected

Credits

  • Legion_TL (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE