{"id":"CVE-2025-68459","title":"RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd","summary":"RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI serv…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"published":"2025-12-18","updated":"2026-09-30","sourceUpdated":"2026-09-30T20:10:00.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-68459","references":[{"url":"https://jvn.jp/en/vu/JVNVU94068946/","label":"vultures@jpcert.or.jp"},{"url":"https://www.ruijie.com.cn/gy/xw-aqtg-gw/930282/","label":"vultures@jpcert.or.jp"}],"tags":["nvd"],"epss":0.01414,"epssPercentile":0.71726,"ingestedAt":"2026-09-30T20:23:19.459Z","slug":"CVE-2025-68459","body":"## Overview\n\nRG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}