Impact
The flaw resides in the user_list_note module of the Ruijie RG‑EW3000GX router, allowing an attacker to inject arbitrary OS commands via the Name argument in the /etc/rg_config/admin file. This vulnerability effectively grants remote command execution on the device, prompting the need for urgent remediation.
Affected Systems
Affected system is the Ruijie RG‑EW3000GX with firmware EW_3.0(1)B11P380. No other versions are documented, so this is the likely scope.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. EPSS of 2% suggests that exploitation is probable, though not widespread, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is remote, likely through web or API interfaces that process the Name parameter; the flaw can be exploited from outside the local network if the device is exposed.
OpenCVE Enrichment