CVE-2025-65363: n/a
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.
AI Analysis
Technical Summary
This vulnerability affects Ruijie APs running AP_RGOS version 11.1. It allows an authenticated user to inject append-style shell commands through the command parameter of the web_action.do endpoint, resulting in root-level command execution. The impact includes unauthorized file disclosure, disruption of device functionality, and the possibility of using the compromised device to pivot within the network. The vulnerability is categorized under CWE-77 (Improper Neutralization of Special Elements used in a Command). No known exploits are reported in the wild, and no patch or vendor advisory has been provided at this time.
Potential Impact
Successful exploitation grants an authenticated attacker root-level command execution on the affected device. This can lead to disclosure of sensitive files, disruption of device operations, and potential lateral movement or pivoting within the network environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated access to the web interface of affected devices and monitor for suspicious activity related to the web_action.do endpoint.
CVE-2025-65363: n/a
Description
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.
CVSS v3.1
Score 7.2high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Ruijie APs running AP_RGOS version 11.1. It allows an authenticated user to inject append-style shell commands through the command parameter of the web_action.do endpoint, resulting in root-level command execution. The impact includes unauthorized file disclosure, disruption of device functionality, and the possibility of using the compromised device to pivot within the network. The vulnerability is categorized under CWE-77 (Improper Neutralization of Special Elements used in a Command). No known exploits are reported in the wild, and no patch or vendor advisory has been provided at this time.
Potential Impact
Successful exploitation grants an authenticated attacker root-level command execution on the affected device. This can lead to disclosure of sensitive files, disruption of device operations, and potential lateral movement or pivoting within the network environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated access to the web interface of affected devices and monitor for suspicious activity related to the web_action.do endpoint.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-11-18T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6936fe0c3bff8e51098be2ed
Added to database: 12/08/2025, 16:34:20 UTC
Last enriched: 07/05/2026, 21:05:43 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 310
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.