PT-2024-2959 · Ruijie · Ruijie Rg-Nbr700Gw

Published

2024-03-29

·

Updated

2025-06-30

·

CVE-2024-28288

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ruijie RG-NBR700GW version 10.3(4b12)
Description The issue is related to a lack of cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can exploit this to log in to the device and disrupt enterprise business. The vulnerability is associated with deficiencies in the password recovery mechanism, allowing a remote attacker to reset or change passwords without knowing the original password.
Recommendations For Ruijie RG-NBR700GW version 10.3(4b12), consider disabling the password reset feature until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of unauthorized login and business disruption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2024-03126
CVE-2024-28288

Affected Products

Ruijie Rg-Nbr700Gw