HIGH
Ruijie RG-EG350 HTTP POST Request setAction os command injection
Published Mar 26, 2024
8.8
HIGHCVSS 3.1
EPSS 3.99%
Description
A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the file /itbox_pi/networksafe.php?a=set of the component HTTP POST Request Handler. The manipulation of the argument bandwidth leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257977 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 20240318StatusaffectedConstraints-
- Version
AND
- ≤ 2024-03-18
-
- Version 20240318StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27853 Advisory
- https://h0e4a0r1t.github.io/2024/vulns/Ruijie%20EG350%20Easy%20Gateway%20Management%20System%20Exists%20Remote%20Code%20Execution%20Vulnerability%20networksafe.php.pdf exploitBroken Link
- https://vuldb.com/?ctiid.257977 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.257977 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.300368 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27853 | Advisory | |
| https://h0e4a0r1t.github.io/2024/vulns/Ruijie%20EG350%20Easy%20Gateway%20Management%20System%20Exists%20Remote%20Code%20Execution%20Vulnerability%20networksafe.php.pdf | exploitBroken Link | |
| https://vuldb.com/?ctiid.257977 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.257977 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.300368 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 26, 2024
Updated Aug 1, 2024
Reserved Mar 26, 2024
Link CVE-2024-2909
CISA Vulnrichment
Updated Jul 10, 2024
ENISA EUVD
EUVD-2024-27853 Assigner VulDB
Published Mar 26, 2024
Updated Aug 1, 2024
Exploited since n/a
Link EUVD-2024-27853