Ruijie Networks · Ruijie Rg-Ew Series Routers · CVE-2021-43162
**Name of the Vulnerable Software and Affected Versions**
Ruijie Networks Ruijie RG-EW Series Routers versions up to ReyeeOS 1.55.1915 / EW 3.0(1)B11P55
**Description**
A Remote Code Execution (RCE) issue exists, allowing for potential code execution. The issue is related to the `runPackDiagnose` function in the "/cgi-bin/luci/api/diagnose" API endpoint.
**Recommendations**
For versions up to ReyeeOS 1.55.1915 / EW 3.0(1)B11P55, as a temporary workaround, consider disabling the `runPackDiagnose` function until a patch is available. Restrict access to the "/cgi-bin/luci/api/diagnose" API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.