# CVE-2025-56129: Ruijie RG-BCR OS Command Injection Vulnerability ## Affect Product **CVE ID:** CVE-2025-56129 **Vendor:** Ruijie Networks **Product:** RG-BCR **Affected Versions:** RG-BCR RG-BCR860 **Vulnerability Type:** OS Command Injection (CWE-78) **Attack Vector:** Network (Remote) **Severity:** Critical ## Vulnerability Summary An OS command injection vulnerability exists in Ruijie RG-BCR. Authenticated remote attackers can execute arbitrary system commands on the device by sending specially crafted POST requests to the vulnerable Lua services. ## Proof of Concept https://1drv.ms/t/c/12406a392c92914b/EQmX513tqd9FsnRiAGdj91kBGDf1VesVC-gFltZ2arfLBA?e=Le5ON3 https://1drv.ms/t/c/12406a392c92914b/EaJ2e_mzgltOiHqb4t8xIvgBoT2CYEP0nrhZd7IYlCHSPQ?e=miUrrL https://1drv.ms/f/c/12406a392c92914b/EqEQemupso9DldgG-EcUI8IBLpEWP_S-f6vpeUtYztYYCg?e=gX4A10