OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.
| Software | From | Fixed in |
|---|---|---|
| ruijie / rg-ew3200gx_firmware | 3.0(1)b11p219 | 3.0(1)b11p219.x |
| ruijie / rg-x60_pro_firmware | 1.021.2014 | 1.021.2014.x |