Vulnerability record · CVE-2023-3450 · published 28 June 2023
CVE-2023-3450: Ruijie RG-BCR860 Network Diagnostic Page OS Command Injection
Ruijie · Rg Bcr860 Firmware
Ruijie RG-BCR860 firmware 2.5.13 contains an OS command injection flaw in the Network Diagnostic Page. A remote attacker who can reach that page can inject operating system commands, and a public exploit has been disclosed. The vendor was contacted but did not respond, so no official fix is known.
Description
A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232547. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote OS command injection with a public exploit and very high EPSS, but exploitation requires administrative privileges and no KEV listing is present.
What it is
Ruijie RG-BCR860 firmware 2.5.13 contains an OS command injection flaw in the Network Diagnostic Page. A remote attacker who can reach that page can inject operating system commands, and a public exploit has been disclosed. The vendor was contacted but did not respond, so no official fix is known.
Impact
Successful exploitation lets an attacker execute arbitrary OS commands on the device, leading to full compromise of confidentiality, integrity and availability. Because the device is a router, this can expose or disrupt the network it serves.
Attack surface
The flaw is reachable over the network via the Network Diagnostic Page. The CVSS vector indicates high privileges are required (PR:H) and no user interaction (UI:N), so an attacker needs valid administrative access to the interface.
Exploitation
A public exploit is referenced (Exploit tag on the GitHub advisory), and EPSS is 0.5083 (98.9th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded.
What to do
- Apply any vendor firmware update for RG-BCR860 if and when Ruijie releases one; no patch is confirmed in this record.
- If no fix exists, restrict access to the device management interface to trusted management networks only.
- Change default administrative credentials and enforce strong, unique passwords for the web UI.
- Disable or block the Network Diagnostic Page if it is not required for operations.
- Monitor vendor advisories and replace the device if it reaches end of support without a fix.
Detection
- Review device and web server logs for requests to the Network Diagnostic Page containing shell metacharacters or unexpected command strings.
- Monitor for unexpected outbound connections or processes spawned by the router's diagnostic functionality.
- Alert on authentication to the management interface from unusual source IPs or outside management hours.
- Compare running configuration and firmware against a known-good baseline to spot unauthorized changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/RCEraser/cve/blob/main/RG-BCR860.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.232547 | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.232547 | Third Party AdvisoryVDB Entry |
| https://github.com/RCEraser/cve/blob/main/RG-BCR860.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.232547 | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.232547 | Third Party AdvisoryVDB Entry |
Track CVE-2023-3450 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-3450), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.