A vulnerability was found in Ruijie RG-UAC up to 1
Description
A vulnerability was found in Ruijie RG-UAC up to 1
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
45 vulnerabilities from Ruijie
← Back to all CVEsA vulnerability was found in Ruijie RG-UAC up to 1
A vulnerability was found in Ruijie RG-UAC up to 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in Ruijie EG105G-P 2
A security flaw has been discovered in Ruijie EG105G-P 2
---METADATA---
VENDOR: Ruijie
PRODUCT: EG105G-P
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
A security flaw has been discovered in the Ruijie EG105G-P network gateway, potentially compromising device security.
Executive Summary:
A critical security flaw in the Ruijie EG105G-P network gateway exposes the device to potential unauthorized access or control.
Vulnerability Details
CVE-ID: CVE-2026-12197
Affected Software: Ruijie EG105G-P
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This flaw affects the Ruijie EG105G-P gateway. Given the nature of network hardware vulnerabilities, it is likely that this issue could be exploited by remote, unauthenticated attackers to gain unauthorized control over the gateway device.
Business Impact
The CVSS score of 7.2 indicates a high-severity risk. A compromised gateway can serve as a pivot point for attackers to intercept network traffic, launch man-in-the-middle attacks, or gain unauthorized access to the internal network, causing significant reputational and operational damage.
Remediation Plan
Immediate Action: Check the Ruijie support website for firmware updates and apply them to all affected EG105G-P units.
Proactive Monitoring: Monitor network traffic for unusual outbound connections or attempts to access the management interface from unauthorized subnets.
Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses and disable unnecessary management services.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of June 15, 2026, there is no public information indicating active exploitation of this vulnerability. Due to the device's role as a network perimeter gateway, the potential for exploitation is extremely high.
Analyst Recommendation
Urgent action is required to patch this network gateway. Failure to secure the perimeter device could lead to a full compromise of the internal network infrastructure. Ensure all management consoles are isolated from public access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co
RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality
Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality
Executive Summary:
A high-severity vulnerability has been identified in the SSH server functionality of multiple Ruijie Networks RG-EST300 devices. This flaw could allow a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to affected systems, potentially leading to a compromise of the network device and the broader internal network.
Vulnerability Details
CVE-ID: CVE-2025-58778
Affected Software: Ruijie Networks RG-EST300
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability exists within the SSH server implementation on the affected Ruijie Networks devices. A flaw in the processing of authentication packets allows a remote, unauthenticated attacker to bypass the authentication mechanism. By sending a specially crafted sequence of SSH packets to a vulnerable device, an attacker can exploit this flaw to gain privileged shell access without providing valid credentials.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 7.2. Successful exploitation could grant an attacker administrative control over the affected network infrastructure device. This could lead to a complete compromise of the device, allowing the attacker to monitor sensitive network traffic, alter network configurations to redirect data, launch further attacks against the internal network (pivoting), or cause a denial-of-service condition. The potential business impact includes data breaches, significant network downtime, and loss of trust in the organization's security posture.
Remediation Plan
Immediate Action: Apply vendor security updates immediately. After patching, it is critical to monitor for any signs of exploitation attempts and review historical SSH access logs for indicators of compromise that may have occurred prior to remediation.
Proactive Monitoring: Security teams should actively monitor for unusual SSH connection attempts (default TCP port 22) targeting affected devices, especially from untrusted or external IP addresses. Scrutinize SSH logs for anomalous successful logins that do not correlate with legitimate administrative activity. Implement alerts for any unauthorized configuration changes or unexpected system reboots on these devices.
Compensating Controls: If immediate patching is not feasible, restrict SSH access to the devices' management interfaces using strict firewall rules or access control lists (ACLs), permitting connections only from a dedicated and trusted management network. If SSH is not essential for the device's operation, consider disabling the service entirely as a temporary mitigation measure.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of October 17, 2025, there is no known public proof-of-concept exploit code for this vulnerability. However, given the nature of the flaw (authentication bypass on network equipment), it is highly likely that security researchers and threat actors will develop exploit code by reverse-engineering the vendor patch.
Analyst Recommendation
Due to the High severity (CVSS 7.2) of this vulnerability, which allows for remote authentication bypass, immediate action is required. We strongly recommend that all organizations using the affected Ruijie Networks RG-EST300 devices apply the vendor-supplied security patches on an emergency basis. Although this CVE is not currently on the CISA KEV list, the risk of future exploitation is significant. Prioritize patching for all internet-facing devices immediately, followed by internal devices, and implement the recommended compensating controls and monitoring where patching is delayed.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providi...
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administ...
Executive Summary:
A critical authentication bypass vulnerability has been identified in certain Ruijie network switches. This flaw allows a remote, unauthenticated attacker to gain complete administrative control over affected devices, posing a severe risk of network disruption, configuration changes, and data interception.
Vulnerability Details
CVE-ID: CVE-2025-56752
Affected Software: Ruijie Multiple Products
Affected Versions: The vulnerability is confirmed in RG-ES series switch firmware ESW_1.0(1)B1P39. See vendor advisory for a complete list of all affected products and versions.
Vulnerability: This is a remote authentication bypass vulnerability. An unauthenticated attacker can exploit a flaw in the device's authentication mechanism, likely via a specially crafted network request to the management interface, to gain full administrative privileges without providing valid credentials. Successful exploitation grants the attacker the same level of access as a legitimate administrator, allowing them to view and modify the device's entire configuration, monitor network traffic, and disable security features.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.4. Exploitation could have a significant business impact, leading to a complete compromise of the network segment managed by the affected switch. An attacker with administrative control could re-route, intercept, or drop network traffic, causing widespread service outages (Denial of Service). Furthermore, the attacker could capture sensitive data, alter network configurations to enable further attacks (lateral movement), or install persistent backdoors, severely impacting data confidentiality, integrity, and availability.
Remediation Plan
Immediate Action: The primary remediation is to apply the vendor-supplied security patches immediately. Organizations should update the firmware on all affected Ruijie products to the latest version as recommended by the vendor. After patching, administrators should review access logs for any signs of unauthorized access or configuration changes that may have occurred prior to the update.
Proactive Monitoring: Implement enhanced monitoring of all affected network devices. Security teams should configure alerts and review logs for any unusual administrative login attempts, particularly from untrusted or internal IP addresses that do not belong to network administrators. Monitor for unexpected configuration changes, the creation of new user accounts, or abnormal traffic patterns originating from the switch's management interface.
Compensating Controls: If immediate patching is not feasible, implement compensating controls to reduce the risk of exploitation. Restrict network access to the switch's management interface using strict Access Control Lists (ACLs) or firewall rules, ensuring it is only accessible from a dedicated and secured management VLAN or specific trusted IP addresses. Disable management access from the public internet or any untrusted network segments.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Sep 3, 2025, there are no known public proof-of-concept exploits or reports of this vulnerability being actively exploited in the wild. However, due to the critical nature of authentication bypass vulnerabilities in network infrastructure devices, it is highly probable that threat actors will develop exploits by reverse-engineering the patch.
Analyst Recommendation
Given the critical CVSS score of 9.4 and the potential for complete network compromise, this vulnerability requires immediate attention. We strongly recommend that organizations prioritize the deployment of the vendor-provided firmware updates to all affected Ruijie devices. While this CVE is not currently listed on the CISA KEV (Known Exploited Vulnerabilities) catalog, its severity makes it a prime candidate for future inclusion. If patching cannot be performed immediately, the compensating controls outlined above must be implemented as a matter of urgency to limit the attack surface.
Update A vulnerability in the Ruijie Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3
OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the actio...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_wanobj in file /usr/lib/lua/luci/controller/admin/common
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a craf...
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request t...
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie M18 EW_3
OS Command Injection vulnerability in Ruijie M18 EW_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the netwo...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the network_set_wan_conf in file /usr/lib/lua/luci/controller/admin/netport
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the actio...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_wireless in file /usr/lib/lua/luci/control/admin/wireless
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request t...
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the subm...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST...
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST...
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie M18 EW_3
OS Command Injection vulnerability in Ruijie M18 EW_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-YST AP_3
OS Command Injection vulnerability in Ruijie RG-YST AP_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request t...
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a craf...
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the rest...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restart_modules in file /usr/lib/lua/luci/controller/admin/common
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request t...
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/host_access_delay
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request t...
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST reques...
OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST...
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie M18 EW_3
OS Command Injection vulnerability in Ruijie M18 EW_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the actio...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service in file /usr/lib/lua/luci/controller/admin/service
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump in file /usr/lib/lua/luci/controller/admin/common_tcpdump
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a craf...
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request t...
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_networkId_merge
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the chec...
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the check_changes in file /usr/lib/lua/luci/controller/admin/common
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1
OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the...
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Ruijie Networks Switch eWeb S29_RGOS 11
Ruijie Networks Switch eWeb S29_RGOS 11
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Ruijie
PRODUCT: RG-UAC
AFFECTED_VERSIONS: Ruijie RG-UAC versions up to 1.0-R1.8.2.p5
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
An unrestricted file upload vulnerability in Ruijie RG-UAC allows remote attackers to upload arbitrary files by manipulating the 'upload_image' argument in 'user_auth_commit.php'.
Executive Summary:
An unrestricted file upload vulnerability in Ruijie RG-UAC permits unauthenticated remote attackers to execute arbitrary code by uploading malicious files to the system.
Vulnerability Details
CVE-ID: CVE-2026-14736
Affected Software: Ruijie RG-UAC
Affected Versions: Ruijie RG-UAC versions up to 1.0-R1.8.2.p5
Vulnerability: The vulnerability resides in the
user_auth_commit.phpfile, which fails to properly validate file types during the upload process. This allows an unauthenticated remote attacker to bypass security controls and upload malicious files via theupload_imageargument.Business Impact
The CVSS score of 7.3 (High) reflects the critical nature of unrestricted file upload vulnerabilities, which often lead to Remote Code Execution (RCE). Successful exploitation could allow an attacker to gain full control over the affected appliance, resulting in complete system compromise and potential lateral movement within the network.
Remediation Plan
Immediate Action: Apply the latest vendor security updates provided by Ruijie. If updates are unavailable, disable the affected file upload functionality if not strictly required for business operations.
Proactive Monitoring: Monitor the filesystem for unexpected executable files or scripts in directories where images or user-submitted content are stored.
Compensating Controls: Utilize a WAF to restrict file upload types and enforce strict access controls on the
user_auth_commit.phpendpoint.Exploitation Status
Public Exploit Available: True
Analyst Notes: As of July 6, 2026, there is no public information indicating active exploitation of this vulnerability. However, the presence of public exploit details significantly lowers the barrier for entry for malicious actors.
Analyst Recommendation
This vulnerability represents a severe risk due to the potential for arbitrary code execution. Organizations using Ruijie RG-UAC must prioritize applying the latest firmware or security patches to mitigate the risk of unauthorized system access.