9.8

CVE-2023-34644

Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RuijieRg-ew1200r Firmware Version3.0(1)b11p204
   RuijieRg-ew1200r Version-
RuijieRg-ew300 Firmware Version3.0(1)b11p204
   RuijieRg-ew300 Version-
RuijieRg-ew3200gx Firmware Version3.0(1)b11p204
   RuijieRg-ew3200gx Version-
RuijieRg-ew1200g Firmware Version3.0(1)b11p204
   RuijieRg-ew1200g Version-
RuijieRg-ew1800gx Firmware Version3.0(1)b11p204
   RuijieRg-ew1800gx Version-
RuijieRg-ew300r Firmware Version3.0(1)b11p204
   RuijieRg-ew300r Version-
RuijieRg-ew1200 Firmware Version3.0(1)b11p204
   RuijieRg-ew1200 Version-
RuijieRg-eg3000xe Firmware Version3.0(1)b11p216
   RuijieRg-eg3000xe Version-
RuijieRg-eg105g Firmware Version3.0(1)b11p216
   RuijieRg-eg105g Version-
RuijieRg-eg305gh-p-e Firmware Version3.0(1)b11p216
   RuijieRg-eg305gh-p-e Version-
RuijieRg-eg105g-p Firmware Version3.0(1)b11p216
   RuijieRg-eg105g-p Version-
RuijieRg-eg3230 Firmware Version3.0(1)b11p216
   RuijieRg-eg3230 Version-
RuijieRg-eg1000e Firmware Version3.0(1)b11p216
   RuijieRg-eg1000e Version-
RuijieRg-eg105g-e Firmware Version3.0(1)b11p216
   RuijieRg-eg105g-e Version-
RuijieRg-eg105gw(t) Firmware Version3.0(1)b11p216
   RuijieRg-eg105gw(t) Version-
RuijieRg-eg105gw-x Firmware Version3.0(1)b11p216
   RuijieRg-eg105gw-x Version-
RuijieRg-eg2000ce Firmware Version3.0(1)b11p216
   RuijieRg-eg2000ce Version-
RuijieRg-eg2100-p Firmware Version3.0(1)b11p216
   RuijieRg-eg2100-p Version-
RuijieRg-eg209gs Firmware Version3.0(1)b11p216
   RuijieRg-eg209gs Version-
RuijieRg-eg310gh-e Firmware Version3.0(1)b11p216
   RuijieRg-eg310gh-e Version-
RuijieRg-eg3000eu Firmware Version3.0(1)b11p216
   RuijieRg-eg3000eu Version-
RuijieRg-eg210g-p Firmware Version3.0(1)b11p216
   RuijieRg-eg210g-p Version-
RuijieRg-eg3250 Firmware Version3.0(1)b11p216
   RuijieRg-eg3250 Version-
RuijieRe-eg1000m Firmware Version3.0(1)b11p216
   RuijieRe-eg1000m Version-
RuijieRg-eg1000c Firmware Version3.0(1)b11p216
   RuijieRg-eg1000c Version-
RuijieRg-nbs3100-48gt4sfp-p Firmware Version3.0(1)b11p218
   RuijieRg-nbs3100-48gt4sfp-p Version-
RuijieRg-nbs3200-24gt4xs Firmware Version3.0(1)b11p218
   RuijieRg-nbs3200-24gt4xs Version-
RuijieRg-nbs3200-24sfp Firmware Version3.0(1)b11p218
   RuijieRg-nbs3200-24sfp Version-
RuijieRg-nbs3200-8gt4xs Firmware Version3.0(1)b11p218
   RuijieRg-nbs3200-8gt4xs Version-
RuijieRg-nbs3200-24gt4xs-p Firmware Version3.0(1)b11p218
   RuijieRg-nbs3200-24gt4xs-p Version-
RuijieRg-nbs3200-48gt4xs Firmware Version3.0(1)b11p218
   RuijieRg-nbs3200-48gt4xs Version-
RuijieRg-nbs3200-48gt4xs-p Firmware Version3.0(1)b11p218
   RuijieRg-nbs3200-48gt4xs-p Version-
RuijieRg-nbs3100-24gt4sfp Firmware Version3.0(1)b11p218
   RuijieRg-nbs3100-24gt4sfp Version-
RuijieRg-nbs3100-24gt4sfp-p Firmware Version3.0(1)b11p218
   RuijieRg-nbs3100-24gt4sfp-p Version-
RuijieRg-nbs3100-8gt2sfp Firmware Version3.0(1)b11p218
   RuijieRg-nbs3100-8gt2sfp Version-
RuijieRg-nbs3100-8gt2sfp-p Firmware Version3.0(1)b11p218
   RuijieRg-nbs3100-8gt2sfp-p Version-
RuijieRg-rap1260 Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap1260 Version-
RuijieRg-rap2266 Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap2266 Version-
RuijieRg-rap1261 Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap1261 Version-
RuijieRg-rap73hd Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap73hd Version-
RuijieRg-rap2200(e) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap2200(e) Version-
RuijieRg-rap6260(h) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap6260(h) Version-
RuijieRg-rap1200(p) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap1200(p) Version-
RuijieRg-rap2260(e) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap2260(e) Version-
RuijieRg-rap6262(g) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap6262(g) Version-
RuijieRg-rap6262 Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap6262 Version-
RuijieRg-rap2260 Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap2260 Version-
RuijieRg-rap6202(g) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap6202(g) Version-
RuijieRg-rap1201 Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap1201 Version-
RuijieRg-rap1200(f) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap1200(f) Version-
RuijieRg-rap2260(f) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap2260(f) Version-
RuijieRg-rap2200(f) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap2200(f) Version-
RuijieRg-rap6260(g) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap6260(g) Version-
RuijieRg-rap2260(g) Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap2260(g) Version-
RuijieRg-rap6260(h)-d Firmware Versionap_3.0(1)b11p218
   RuijieRg-rap6260(h)-d Version-
RuijieRg-nbc256 Firmware Versionac_3.0(1)b11p86
   RuijieRg-nbc256 Version-
RuijieRg-nbc512 Firmware Versionac_3.0(1)b11p86
   RuijieRg-nbc512 Version-
RuijieRg-s1930-24gt4sfp Firmware Version3.0(1)b11p218
   RuijieRg-s1930-24gt4sfp Version-
RuijieRg-s1930-24t4sfp-p Firmware Version3.0(1)b11p218
   RuijieRg-s1930-24t4sfp-p Version-
RuijieRg-s1930-8gt2sfp Firmware Version3.0(1)b11p218
   RuijieRg-s1930-8gt2sfp Version-
RuijieRg-s1930-8gt2sfp-p Firmware Version3.0(1)b11p218
   RuijieRg-s1930-8gt2sfp-p Version-
RuijieRg-s1930-8t2sfp-p Firmware Version3.0(1)b11p218
   RuijieRg-s1930-8t2sfp-p Version-
RuijieRg-s1930-24t4sfp Firmware Version3.0(1)b11p218
   RuijieRg-s1930-24t4sfp Version-
RuijieRg-s1930-24gt4sfp-p Firmware Version3.0(1)b11p218
   RuijieRg-s1930-24gt4sfp-p Version-
RuijieRg-s1930-8t2sfp Firmware Version3.0(1)b11p218
   RuijieRg-s1930-8t2sfp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.54% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.