Ruijie has 3 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The median CVSS is 9.1 (critical), with 2 rated critical. The most common weakness class is CWE-77 (3). Most affected products: RG-EW3000GX (2), rg-ap720-l_firmware (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2026-92398Critical· 9.1A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P38063CVE-2026-92397Critical· 9.1A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P38063CVE-2025-65363High· 7.2Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the …41
Ruijie vulnerabilities
CVEs affecting Ruijie, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-92398Critical· 9.1PoCA vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380
A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Nam…
CVE-2026-92397Critical· 9.1PoCA vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads t…
CVE-2025-65363High· 7.2Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the …
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the …