Description

Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.

INFO

Published Date :

2025-12-08T00:00:00.000Z

Last Modified :

2025-12-08T21:44:27.708Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-65363 vulnerability.

Vendors Products
Ruijie
  • Rg-ap720-l
  • Rg-ap720-l Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-65363.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact