CVE-2025-65363

HIGH

Ruijie RG-AP720-L Firmware 11.1.0-11.1(9)B1P21 - Authenticated Command Injection via web_action.do Command Parameter

Title source: llm
STIX 2.1

Description

Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.

Scores

CVSS v3 7.2
EPSS 0.0565
EPSS Percentile 92.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
ruijie/rg-ap720-l_firmware 11.1.0 - 11.1\(9\)B1P21
Published Dec 08, 2025
Tracked Since Feb 18, 2026