peter bassill · operator
$ cve CVE-2026-92398 JSON

CVE-2026-92398

9.1
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS3.18% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2026-09-16
Last modified2026-09-16

References

→ the Explorer  ·  watch your stack  ·  NVD