<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>RG-EW3000GX (EW_3.0(1)B11P380) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/rg-ew3000gx-ew_3.01b11p380/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 17:51:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/rg-ew3000gx-ew_3.01b11p380/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in Ruijie RG-EW3000GX</title><link>https://feed.craftedsignal.io/briefs/2026-09-ruijie-rce/</link><pubDate>Wed, 16 Sep 2026 17:51:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ruijie-rce/</guid><description>A critical remote OS command injection vulnerability in the Ruijie RG-EW3000GX router allows unauthenticated attackers to execute arbitrary commands via the configChange component.</description><content:encoded><![CDATA[<p>A critical security vulnerability (CVE-2026-92397) has been identified in the Ruijie RG-EW3000GX router, specifically within firmware version EW_3.0(1)B11P380. The vulnerability exists within the 'cc_set' function of the 'unifyframe-sgi.elf' binary, which is part of the 'configChange' component. An attacker can trigger this vulnerability by supplying a malicious payload to the 'data.url' argument. Because the router fails to properly sanitize this input before passing it to the underlying operating system, remote attackers can achieve command injection. This flaw is particularly dangerous as it allows for unauthenticated remote code execution on the networking device, potentially leading to a full compromise of the router, interception of network traffic, or use of the device as a pivot point within the local network. Proof-of-concept exploits have been disclosed publicly, making the risk of exploitation high.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify exposed management interfaces for Ruijie RG-EW3000GX devices.</li>
<li>Attacker crafts an HTTP request targeting the 'configChange' component exposed on the device.</li>
<li>Attacker injects a malicious command string into the 'data.url' parameter of the 'cc_set' function call.</li>
<li>The web service forwards the unsanitized input to the 'unifyframe-sgi.elf' binary.</li>
<li>The binary executes the injected command with the privileges of the web service process.</li>
<li>The attacker establishes a reverse shell or downloads additional payloads to maintain persistent access to the device.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-92397 grants an attacker unauthenticated remote code execution on the target router. Impact includes the ability to bypass network segmentation, perform man-in-the-middle attacks on connected clients, exfiltrate credentials, and utilize the compromised router as a permanent persistence mechanism or bridge into the internal network environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Immediately audit perimeter network logs for any HTTP requests containing command injection characters directed at Ruijie RG-EW3000GX devices.</li>
<li>Patch or update the router firmware to a version beyond EW_3.0(1)B11P380 if available, or restrict access to the device management interface to trusted internal IP ranges only.</li>
<li>If a patch is unavailable, place affected devices behind a firewall and block external access to administrative endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>cve-2026-92398</category><category>command-injection</category></item></channel></rss>