Back

CRITICAL

Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php

Published Nov 24, 2025

Description

Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-14 UTC.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Nov 24, 2025
Updated Nov 25, 2025
Reserved Nov 24, 2025
CISA Vulnrichment
Updated Nov 24, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Nov 24, 2025
Updated Nov 25, 2025
Exploited since n/a
EUVD-2025-198992