CVE-2025-65363: Ruijie Rg-AP720-L Firmware
High severity, CVSS 7.2. EPSS: 6.7% chance of exploitation in the next 30 days.
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.
Affected products
- Ruijie Rg-AP720-L Firmware: from 11.1.0, up to and including 11.1\(9\)B1P21
Published 2025-12-08. Last modified 2026-07-05.