CVE-2025-68459

HIGH

Ruijie Networks AP180 Series < AP_RGOS 11.9(4)B1P8 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.

References (2)

Core 2
Core References

Scores

CVSS v3 7.2
EPSS 0.0126
EPSS Percentile 65.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (9)
Ruijie Networks Co., Ltd./AP180(JA) V1.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180(JA) V2.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180(JP) V1.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180-AC V1.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180-AC V2.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180-AC V3.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180-PE V1.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180-PE V2.xx AP_RGOS 11.9(4)B1P8 and earlier
Ruijie Networks Co., Ltd./AP180-PE V3.xx AP_RGOS 11.9(4)B1P8 and earlier
Published Dec 18, 2025
Tracked Since Feb 18, 2026