{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-92398/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:ruijie:rg-ew3000gx:ew_3.0\\(1\\)b11p380:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-92397"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RG-EW3000GX (EW_3.0(1)B11P380)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","cve-2026-92398","command-injection"],"_cs_type":"advisory","_cs_vendors":["Ruijie"],"content_html":"\u003cp\u003eA critical security vulnerability (CVE-2026-92397) has been identified in the Ruijie RG-EW3000GX router, specifically within firmware version EW_3.0(1)B11P380. The vulnerability exists within the 'cc_set' function of the 'unifyframe-sgi.elf' binary, which is part of the 'configChange' component. An attacker can trigger this vulnerability by supplying a malicious payload to the 'data.url' argument. Because the router fails to properly sanitize this input before passing it to the underlying operating system, remote attackers can achieve command injection. This flaw is particularly dangerous as it allows for unauthenticated remote code execution on the networking device, potentially leading to a full compromise of the router, interception of network traffic, or use of the device as a pivot point within the local network. Proof-of-concept exploits have been disclosed publicly, making the risk of exploitation high.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify exposed management interfaces for Ruijie RG-EW3000GX devices.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the 'configChange' component exposed on the device.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious command string into the 'data.url' parameter of the 'cc_set' function call.\u003c/li\u003e\n\u003cli\u003eThe web service forwards the unsanitized input to the 'unifyframe-sgi.elf' binary.\u003c/li\u003e\n\u003cli\u003eThe binary executes the injected command with the privileges of the web service process.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes a reverse shell or downloads additional payloads to maintain persistent access to the device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-92397 grants an attacker unauthenticated remote code execution on the target router. Impact includes the ability to bypass network segmentation, perform man-in-the-middle attacks on connected clients, exfiltrate credentials, and utilize the compromised router as a permanent persistence mechanism or bridge into the internal network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit perimeter network logs for any HTTP requests containing command injection characters directed at Ruijie RG-EW3000GX devices.\u003c/li\u003e\n\u003cli\u003ePatch or update the router firmware to a version beyond EW_3.0(1)B11P380 if available, or restrict access to the device management interface to trusted internal IP ranges only.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, place affected devices behind a firewall and block external access to administrative endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T17:51:40Z","date_published":"2026-09-16T17:51:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ruijie-rce/","summary":"A critical remote OS command injection vulnerability in the Ruijie RG-EW3000GX router allows unauthenticated attackers to execute arbitrary commands via the configChange component.","title":"Remote Command Injection in Ruijie RG-EW3000GX","url":"https://feed.craftedsignal.io/briefs/2026-09-ruijie-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-92398","version":"https://jsonfeed.org/version/1.1"}