CVE-2025-56099 | Ruijie RG-YST 3.0(1)B11P280YST250F POST common.lua pwdmodify os command injection
A vulnerability classified as critical was found in Ruijie RG-YST 3.0(1)B11P280YST250F. Impacted is the function pwdmodify in the library /usr/lib/lua/luci/modules/common.lua of the component POST Handler. The manipulation results in os command injection.
This vulnerability is known as CVE-2025-56099. It is possible to launch the attack remotely. No exploit is available.