---
id: CVE-2026-92397
title: A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380
summary: >-
  A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380.
  Affected by this vulnerability is the function cc_set of the file
  unifyframe-sgi.elf of the component configChange. Such manipulation of the
  argument data.url leads t…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-77
  - CWE-78
vendor: Ruijie
product: RG-EW3000GX
affected:
  - RG-EW3000GX EW_3.0(1)B11P380
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:17:48.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92397'
references:
  - url: >-
      https://github.com/FoundTL/RG-EW3000GX/blob/main/RG-EW3000GX_unifyframe-sgi.elf.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92397'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/940161'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405549'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405549/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T19:34:38.849852Z'
ingestedAt: '2026-09-16T15:58:38.771Z'
epss: 0.02299
epssPercentile: 0.82558
---

## Overview

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
