PT-2023-24965 · Ruijie Networks · Nbc+6

Wang Jincheng

·

Published

2023-07-31

·

Updated

2024-05-14

·

CVE-2023-34644

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ruijie Networks RG-EW series home routers and repeaters version EW 3.0(1)B11P204 Ruijie Networks RG-NBS and RG-S1930 series switches version SWITCH 3.0(1)B11P218 Ruijie Networks RG-EG series business VPN routers version EG 3.0(1)B11P216 Ruijie Networks EAP and RAP series wireless access points version AP 3.0(1)B11P218 Ruijie Networks NBC series wireless controllers version AC 3.0(1)B11P86
Description The issue allows unauthorized remote attackers to gain the highest privileges via a crafted POST request to "/cgi-bin/luci/api/auth". This enables remote attackers to gain escalated privileges.
Recommendations For Ruijie Networks RG-EW series home routers and repeaters version EW 3.0(1)B11P204, consider disabling access to the "/cgi-bin/luci/api/auth" endpoint until a patch is available. For Ruijie Networks RG-NBS and RG-S1930 series switches version SWITCH 3.0(1)B11P218, restrict access to the "/cgi-bin/luci/api/auth" endpoint to minimize the risk of exploitation. For Ruijie Networks RG-EG series business VPN routers version EG 3.0(1)B11P216, avoid using the vulnerable API endpoint until the issue is resolved. For Ruijie Networks EAP and RAP series wireless access points version AP 3.0(1)B11P218, consider temporarily disabling the API endpoint "/cgi-bin/luci/api/auth" to prevent exploitation. For Ruijie Networks NBC series wireless controllers version AC 3.0(1)B11P86, limit access to the vulnerable endpoint to reduce the risk of attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-34644

Affected Products

Eap
Nbc
Rap
Rg-Eg
Rg-Ew
Rg-Nbs
Rg-S1930