CVE-2026-23699 Details
Description
AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exploited, arbitrary commands may be executed on the devices.
An OS command injection vulnerability has been identified in the Ruijie Networks AP180 series access points, specifically in firmware versions prior to AP_RGOS 11.9(4)B1P8. This vulnerability allows logged-in users with administrative privileges to execute arbitrary OS commands on the affected devices.
Users are advised to update the firmware to version AP_RGOS 11.9(4)B1P8 or later. If the update cannot be applied, it is recommended to restrict web access to trusted source IP addresses using ACL or whitelist configurations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 22, 2026CISA-ADP
Assessed Jan 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN86850670/ | [email protected] | AdvisoryRemedy |
| https://www.ruijie.co.jp/products/rg-ap180-pe_p432111650928590848.html#productDocument | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ruijie Networks AP180-JA | All versions |
CPE
Remediation
| |
| Ruijie Networks AP180-JP | All versions |
CPE
Remediation
| |
| Ruijie Networks AP180-AC | All versions |
CPE
Remediation
| |
| Ruijie Networks AP180-PE | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2026 | New CVE Received | [email protected] |
Volerion