Summary

Certain Ruijie switch and router products are affected by multiple vulnerabilities, including a web interface denial-of-service (DoS) vulnerability, an authenticated command injection vulnerability, and an unauthenticated information disclosure vulnerability. [Vulnerability ID: RJPSIRT-2026-08130]

Software Versions and Fixes

Affected Product
Affected Version
Repair Version
RG-CS85
Versions prior to 12.6(4)B0703P1
12.6(4)B0703P1 and later versions
RSR860-NR
Versions prior to RSR860-NR_RGOS 12.6(4)B1613
RSR860-NR_RGOS 12.6(4)B1613 and later versions
RSR20-X1
Versions prior to RGOS 12.6(4)B1418
RGOS 12.6(4)B1418 and later versions
RSR20-XA
Versions prior to RGOS 12.6(4)B1418
RGOS 12.6(4)B1418 and later versions
RSR30-XA
Versions prior to RGOS 12.6(4)B1315
RGOS 12.6(4)B1315 and later versions
RSR50-XA
Versions prior to RGOS 12.6(4)B1214
RGOS 12.6(4)B1214 and later versions
RSR77-XA
Versions prior to RGOS 12.6(4)B0915
RGOS 12.6(4)B0915 and later versions
RSR830
Versions prior to RGOS 12.6(4)B1812
RGOS 12.6(4)B1812 and later versions
S7600
Versions prior to S7600_RGOS 12.6(4)B1510P2
S7600_RGOS 12.6(4)B1510P2 and later versions
S5350e
Versions prior to S5350E_RGOS 12.6(4)B0703P1
S5350E_RGOS 12.6(4)B0703P1 and later versions
S5750x
Versions prior to S5750X_RGOS 12.6(4)B1002P1
S5750X_RGOS 12.6(4)B1002P1 and later versions
S6150
Versions prior to RGOS 12.6(4)B1309P1
RGOS 12.6(4)B1309P1 and later versions
S5760x
Versions prior to S5760X_RGOS 12.6(4)B0703P1
S5760X_RGOS 12.6(4)B0703P1 and later versions
N18E
Versions prior to RGOS 12.6(4)B0305P2
RGOS 12.6(4)B0305P2 and later versions
Obtaining Fixed Software:
  1. The product that supports automatic update will receive a system update prompt. You can install the update to fix the vulnerability.
  2. Download it from the Ruijie Networks websites.
  3. Contact local after-sales personnel to obtain it.

Vulnerability Scoring

Vulnerabilities are scored based on the CVSS v3.1 scoring system. For details, please refer to: https://www.first.org/cvss/v3.1/specification-document .
Vulnerability
Base score
CVSS v3.1 Vector
information disclosure
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
web interface DoS
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
authenticated command injection
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporary Fix

Configure an access control list (ACL) to allow only specific IP addresses to access the device management interface.

Source

The above vulnerabilities were responsibly disclosed to us by white-hat security researcher Риналь Салимов. Ruijie PSIRT would like to thank him for his support in the discovery, reporting, and coordinated handling of these vulnerabilities.

Revision History

Date
Revision History
2026-08-13
V1.0 Initial Release

Contact Us

Ruijie Networks adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deals with product security issues through our response mechanism.
To enjoy Ruijie Networks PSIRT services and obtain Ruijie Networks product vulnerability information, please visit https://www.ruijienetworks.com/support/securityBulletins .
To report a security vulnerability in Ruijie Networks products and solutions, please send it to  PSIRT@ruijie.com.cn . For details, please visit https://www.ruijienetworks.com/support/securityBulletins/vulnerability_reporting .
You can contact us through the following channels:
  1. Support:https://www.ruijienetworks.com/support
  2. Community:https://community.ruijienetworks.com/portal.php
  3. Live Chat:https://www.ruijienetworks.com/rita