7.2

CVE-2024-5338

Ruijie RG-UAC online.php os command injection

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been classified as critical. Affected is an unknown function of the file /view/vpn/autovpn/online.php. The manipulation of the argument peernode leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266244. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RuijieRg-uac 6000-cc Firmware Version-
   RuijieRg-uac 6000-cc Version-
RuijieRg-uac 6000-e10 Firmware Version-
   RuijieRg-uac 6000-e10 Version-
RuijieRg-uac 6000-e10 Firmware Version-
   RuijieRg-uac 6000-e10 Version3.0
RuijieRg-uac 6000-e10c Firmware Version-
   RuijieRg-uac 6000-e10c Version-
RuijieRg-uac 6000-e20 Firmware Version-
   RuijieRg-uac 6000-e20 Version-
RuijieRg-uac 6000-e20c Firmware Version-
   RuijieRg-uac 6000-e20c Version-
RuijieRg-uac 6000-e20m Firmware Version-
   RuijieRg-uac 6000-e20m Version-
RuijieRg-uac 6000-e50 Firmware Version-
   RuijieRg-uac 6000-e50 Version-
RuijieRg-uac 6000-e50c Firmware Version-
   RuijieRg-uac 6000-e50c Version-
RuijieRg-uac 6000-e50m Firmware Version-
   RuijieRg-uac 6000-e50m Version-
RuijieRg-uac 6000-ea Firmware Version-
   RuijieRg-uac 6000-ea Version-
RuijieRg-uac 6000-ei Firmware Version-
   RuijieRg-uac 6000-ei Version-
RuijieRg-uac 6000-isg02 Firmware Version-
   RuijieRg-uac 6000-isg02 Version-
RuijieRg-uac 6000-isg10 Firmware Version-
   RuijieRg-uac 6000-isg10 Version-
RuijieRg-uac 6000-isg40 Firmware Version-
   RuijieRg-uac 6000-isg40 Version-
RuijieRg-uac 6000-si Firmware Version-
   RuijieRg-uac 6000-si Version-
RuijieRg-uac 6000-u3100 Firmware Version-
   RuijieRg-uac 6000-u3100 Version-
RuijieRg-uac 6000-u3210 Firmware Version-
   RuijieRg-uac 6000-u3210 Version-
RuijieRg-uac 6000-x100 Firmware Version-
   RuijieRg-uac 6000-x100 Version-
RuijieRg-uac 6000-x100s Firmware Version-
   RuijieRg-uac 6000-x100s Version-
RuijieRg-uac 6000-x20 Firmware Version-
   RuijieRg-uac 6000-x20 Version-
RuijieRg-uac 6000-x200 Firmware Version-
   RuijieRg-uac 6000-x200 Version-
RuijieRg-uac 6000-x20m Firmware Version-
   RuijieRg-uac 6000-x20m Version-
RuijieRg-uac 6000-x20me Firmware Version-
   RuijieRg-uac 6000-x20me Version-
RuijieRg-uac 6000-x300d Firmware Version-
   RuijieRg-uac 6000-x300d Version-
RuijieRg-uac 6000-x60 Firmware Version-
   RuijieRg-uac 6000-x60 Version-
RuijieRg-uac 6000-xs Firmware Version-
   RuijieRg-uac 6000-xs Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.87% 0.939
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cna@vuldb.com 5.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 4.7 1.2 3.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 5.8 6.4 6.4
AV:N/AC:L/Au:M/C:P/I:P/A:P
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/z%7CYVDv%7CHKA)*%5CdK!/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-autovpn%3Aonline.php.pdf
Broken Link
https://vuldb.com/?ctiid.266244
VDB Entry
Permissions Required
https://vuldb.com/?id.266244
Third Party Advisory
VDB Entry
https://vuldb.com/?submit.336036
Third Party Advisory
VDB Entry