← Vulnerability feed

Vulnerability record · CVE-2023-3450 · published 28 June 2023

CVE-2023-3450: Ruijie RG-BCR860 Network Diagnostic Page OS Command Injection

Ruijie · Rg Bcr860 Firmware

Ruijie RG-BCR860 firmware 2.5.13 contains an OS command injection flaw in the Network Diagnostic Page. A remote attacker who can reach that page can inject operating system commands, and a public exploit has been disclosed. The vendor was contacted but did not respond, so no official fix is known.

7.2 CVSS 3.1 High EPSS 51% · top 1.1% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 5.8
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232547. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote OS command injection with a public exploit and very high EPSS, but exploitation requires administrative privileges and no KEV listing is present.

What it is

Ruijie RG-BCR860 firmware 2.5.13 contains an OS command injection flaw in the Network Diagnostic Page. A remote attacker who can reach that page can inject operating system commands, and a public exploit has been disclosed. The vendor was contacted but did not respond, so no official fix is known.

Impact

Successful exploitation lets an attacker execute arbitrary OS commands on the device, leading to full compromise of confidentiality, integrity and availability. Because the device is a router, this can expose or disrupt the network it serves.

Attack surface

The flaw is reachable over the network via the Network Diagnostic Page. The CVSS vector indicates high privileges are required (PR:H) and no user interaction (UI:N), so an attacker needs valid administrative access to the interface.

Exploitation

A public exploit is referenced (Exploit tag on the GitHub advisory), and EPSS is 0.5083 (98.9th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded.

What to do

  • Apply any vendor firmware update for RG-BCR860 if and when Ruijie releases one; no patch is confirmed in this record.
  • If no fix exists, restrict access to the device management interface to trusted management networks only.
  • Change default administrative credentials and enforce strong, unique passwords for the web UI.
  • Disable or block the Network Diagnostic Page if it is not required for operations.
  • Monitor vendor advisories and replace the device if it reaches end of support without a fix.

Detection

  • Review device and web server logs for requests to the Network Diagnostic Page containing shell metacharacters or unexpected command strings.
  • Monitor for unexpected outbound connections or processes spawned by the router's diagnostic functionality.
  • Alert on authentication to the management interface from unusual source IPs or outside management hours.
  • Compare running configuration and firmware against a known-good baseline to spot unauthorized changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/RCEraser/cve/blob/main/RG-BCR860.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.232547 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.232547 Third Party AdvisoryVDB Entry
https://github.com/RCEraser/cve/blob/main/RG-BCR860.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.232547 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.232547 Third Party AdvisoryVDB Entry

Track CVE-2023-3450 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-56129Ruijie rg-bcr860 firmware os command injection vulnerabilityOS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the acti…EPSS 2.6%8.8CVE-2025-56109Ruijie rg-bcr860 firmware os command injection vulnerabilityOS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the acti…EPSS 3.1%8.8CVE-2025-56110Ruijie rg-bcr860 firmware os command injection vulnerabilityOS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the acti…EPSS 3.1%8.8CVE-2025-56111Ruijie rg-bcr860 firmware os command injection vulnerabilityOS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the netw…EPSS 3.1%8.8CVE-2025-56088Ruijie rg-bcr860 firmware os command injection vulnerabilityOS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the acti…EPSS 3.5%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed

Source: NIST National Vulnerability Database (record CVE-2023-3450), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.