PT-2024-4403 · Ruijie · Ruijie Rg-Uac
Chazzhou
·
Published
2024-06-23
·
Updated
2025-08-21
·
CVE-2024-6269
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ruijie RG-UAC version 1.0
Description
The issue exists due to insufficient input validation in the
get ip.addr details function of the /view/vpn/autovpn/sxh vpnlic.php file. This allows a remote attacker to execute arbitrary commands by manipulating the indevice argument, leading to command injection. The attack can be initiated remotely.Recommendations
For Ruijie RG-UAC version 1.0, consider disabling the
get ip.addr details function until a patch is available. Restrict access to the /view/vpn/autovpn/sxh vpnlic.php file to minimize the risk of exploitation. Avoid using the indevice argument in the affected HTTP POST Request Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruijie Rg-Uac