PT-2026-5289 · Ruijie Networks · Eweb S29 Rgos

Tuygun

·

Published

2026-01-29

·

Updated

2026-05-26

·

CVE-2020-37015

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ruijie Networks Switch eWeb S29 RGOS version 11.4
Description The software contains a directory traversal flaw that permits unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do API endpoint using '../' sequences to retrieve system configuration files, which may contain credentials and network settings.
Recommendations Apply any available updates to address the directory traversal issue in the /download.do endpoint.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-37015

Affected Products

Eweb S29 Rgos