CVE-2025-56110 | Ruijie RG-BCR RG-BCR860 POST rcmsAPI.lua action_deal_update os command injection
A vulnerability, which was classified as critical, was found in Ruijie RG-BCR RG-BCR860. This affects the function action_deal_update in the library /usr/lib/lua/luci/controller/api/rcmsAPI.lua of the component POST Handler. The manipulation results in os command injection.
This vulnerability is known as CVE-2025-56110. It is possible to launch the attack remotely. No exploit is available.