OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.
| Software | From | Fixed in |
|---|---|---|
| ruijie / rg-x60_pro_firmware | 1.021.2014 | 1.021.2014.x |
| ruijie / rg-ew1200_firmware | 3.0(1)b11p301 | 3.0(1)b11p301.x |