Ruijie BCR810W/BCR860 vulnerable to OS command injection


Network router BCR810W/BCR860 provided by Ruijie Networks Co., Ltd. contains an OS command injection vulnerability (CVE-2023-3608, CWE-78).
Note that this vulnerability can only be exploited when the BCOS port of the product is connected to the Internet.

JPCERT/CC has confirmed attacks attempt to exploit this vulnerability.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.8 (Medium) [Other]
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
Affected Products

Ruijie Networks
  • rg-bcr810w firmware
  • rg-bcr860 firmware


An arbitrary OS command may be executed by an authenticated user with the administrative privilege.

[Update the firmware]
The vendor has released firmware BCOS 2.5.15 which fixes this vulnerability.

[Apply workarounds]
The vendor recommends the following workarounds.

* Set a strong administrator password.
* Disable WAN access to the products.
Vendor Information

Ruijie Networks
CWE (What is CWE?)

  1. OS Command Injection(CWE-78) [Other]
CVE (What is CVE?)

  1. CVE-2023-3608

  1. JVN : JVNVU#92249385
  2. National Vulnerability Database (NVD) : CVE-2023-3608
Revision History

  • [2024/05/17]
      Web page was published