---
id: CVE-2025-68459
title: >-
  RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie
  Networks Co., Ltd
summary: >-
  RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie
  Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary
  OS command may be executed on the product by an attacker who logs in to the
  CLI serv…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2025-12-18'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68459'
references:
  - url: 'https://jvn.jp/en/vu/JVNVU94068946/'
    label: vultures@jpcert.or.jp
  - url: 'https://www.ruijie.com.cn/gy/xw-aqtg-gw/930282/'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.01414
epssPercentile: 0.71726
ingestedAt: '2026-09-30T20:23:19.459Z'
---

## Overview

RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
