OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92397

CRITICAL · CVSS 9.1 EPSS 3.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the Ruijie RG-EW3000GX, specifically within the cc_set function of the unifyframe-sgi.elf file, allowing for OS command injection through manipulated argument data.url, which can be exploited remotely. Organizations using this device should prioritize immediate remediation to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92397
Severity
CRITICAL
CVSS
9.1
EPSS
3.18%

Original NVD Description

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.