CVE-2025-65363
HIGHRuijie RG-AP720-L Firmware 11.1.0-11.1(9)B1P21 - Authenticated Command Injection via web_action.do Command Parameter
Title source: llmDescription
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.
References (3)
Core 3
Scores
CVSS v3
7.2
EPSS
0.0565
EPSS Percentile
92.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-77
Status
published
Products (1)
ruijie/rg-ap720-l_firmware
11.1.0 - 11.1\(9\)B1P21
Published
Dec 08, 2025
Tracked Since
Feb 18, 2026