PT-2024-9673 · Ruijie · Ruijie Reyee Os

Published

2024-12-03

·

Updated

2024-12-25

·

CVE-2024-52324

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x
Description The issue is related to the use of an inherently dangerous function in Ruijie Reyee OS, which could allow an attacker to send a malicious MQTT message, resulting in devices executing arbitrary OS commands. This could enable remote attackers to execute commands on affected devices.
Recommendations For Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x, consider disabling the use of MQTT messages until a patch is available, as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-11385
CVE-2024-52324

Affected Products

Ruijie Reyee Os