Impact
The vulnerability exists in the cc_set function of unifyframe-sgi.elf in Ruijie RG-EW3000GX firmware. By manipulating the data.url argument, an attacker can inject arbitrary operating‑system commands. This command injection can let the attacker execute any shell instruction with the privileges of the service, compromising confidentiality, integrity, and availability of the device.
Affected Systems
The affected systems are Ruijie routers model RG‑EW3000GX, specifically firmware EW_3.0(1)B11P380. Only this version is known to contain the vulnerable cc_set implementation.
Risk and Exploitability
The CVSS score of 9.4 indicates high severity, and the EPSS score of 2% shows that exploitation is plausible and currently observed. The vulnerability is not listed in the CISA KEV catalog, but the public exploit disclosure means it can be leveraged remotely by attackers with network access to the device. An attacker who succeeds can run arbitrary commands and effectively gain full control of the device.
OpenCVE Enrichment