Description
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Published: 2026-09-16
Score: 9.4 Critical
EPSS: 3.2% Low
KEV: No
Impact: Remote OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the cc_set function of unifyframe-sgi.elf in Ruijie RG-EW3000GX firmware. By manipulating the data.url argument, an attacker can inject arbitrary operating‑system commands. This command injection can let the attacker execute any shell instruction with the privileges of the service, compromising confidentiality, integrity, and availability of the device.

Affected Systems

The affected systems are Ruijie routers model RG‑EW3000GX, specifically firmware EW_3.0(1)B11P380. Only this version is known to contain the vulnerable cc_set implementation.

Risk and Exploitability

The CVSS score of 9.4 indicates high severity, and the EPSS score of 2% shows that exploitation is plausible and currently observed. The vulnerability is not listed in the CISA KEV catalog, but the public exploit disclosure means it can be leveraged remotely by attackers with network access to the device. An attacker who succeeds can run arbitrary commands and effectively gain full control of the device.

Generated by OpenCVE AI on September 18, 2026 at 05:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s official firmware patch that fixes the cc_set command injection flaw.
  • If an immediate patch is unavailable, restrict access to the configChange functionality by disabling it or removing it from the service stack.
  • Block exposure of the router to the public network: place the device in a demilitarized zone or VLAN that only trusted management hosts can reach.
  • Configure a firewall to allow only known administrative IP ranges and deny all other inbound traffic to the device’s management interfaces.
  • Monitor system logs for anomalous shell command execution or unexpected stderr output and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 18, 2026 at 05:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Title Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection
First Time appeared Ruijie
Ruijie rg-ew3000gx
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:ruijie:rg-ew3000gx:*:*:*:*:*:*:*:*
Vendors & Products Ruijie
Ruijie rg-ew3000gx
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Ruijie Rg-ew3000gx
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T19:34:47.950Z

Reserved: 2026-09-16T08:46:59.082Z

Link: CVE-2026-92397

cve-icon Vulnrichment

Updated: 2026-09-16T19:34:43.267Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T16:17:22.960

Modified: 2026-09-16T20:17:48.090

Link: CVE-2026-92397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:00:14Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')