Description
A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
Published: 2023-08-17
Score: 8.8 High
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-42663 A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
History

Tue, 08 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijie nbc Series Wireless Controllers
Ruijie rg-eg
Ruijie rg-ew
Ruijie rg-ew Series Routers And Repeaters
Ruijie rg-s1930
CPEs cpe:2.3:h:ruijie:nbc_series_wireless_controllers:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-ew:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-ew_series_routers_and_repeaters:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-s1930:*:*:*:*:*:*:*:*
Vendors & Products Ruijie nbc Series Wireless Controllers
Ruijie rg-eg
Ruijie rg-ew
Ruijie rg-ew Series Routers And Repeaters
Ruijie rg-s1930
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ruijie Nbc Series Wireless Controllers Rg-eap101 Rg-eap101 Firmware Rg-eap101 V2 Rg-eap101 V2 Firmware Rg-eap102 Rg-eap102\(f\) Rg-eap102\(f\) Firmware Rg-eap102 Firmware Rg-eap102 V2 Rg-eap102 V2 Firmware Rg-eap162\(g\) Rg-eap162\(g\) Firmware Rg-eap201 Rg-eap201 Firmware Rg-eap202 Rg-eap202 Firmware Rg-eap212\(f\) Rg-eap212\(f\) Firmware Rg-eap212\(g\) Rg-eap212\(g\) Firmware Rg-eap262\(g\) Rg-eap262\(g\) Firmware Rg-eap602 Rg-eap602 Firmware Rg-eap662\(g\) Rg-eap662\(g\) Firmware Rg-eg Rg-eg105g-e Rg-eg105g-e Firmware Rg-eg105g-pe Rg-eg105g-pe Firmware Rg-eg105g V2 Rg-eg105g V2 Firmware Rg-eg210g-e Rg-eg210g-e Firmware Rg-eg210g-p Rg-eg210g-p Firmware Rg-eg210g-pe Rg-eg210g-pe Firmware Rg-ew Rg-ew1200 Rg-ew1200 Firmware Rg-ew1200g Pro Rg-ew1200g Pro Firmware Rg-ew1200r Rg-ew1200r Firmware Rg-ew1300g Rg-ew1300g Firmware Rg-ew1800gx Pro Rg-ew1800gx Pro Firmware Rg-ew3000gx Pro Rg-ew3000gx Pro Firmware Rg-ew300 Pro Rg-ew300 Pro Firmware Rg-ew300r Rg-ew300r Firmware Rg-ew3200gx Pro Rg-ew3200gx Pro Firmware Rg-ew Series Routers And Repeaters Rg-nb3200-24gt4xs Rg-nb3200-24gt4xs Firmware Rg-nbc256 Rg-nbc256 Firmware Rg-nbc512 Rg-nbc512 Firmware Rg-nbs1850gc Rg-nbs1850gc Firmware Rg-nbs1850gc V2 Rg-nbs1850gc V2 Firmware Rg-nbs200 Rg-nbs2000 Rg-nbs2000 Firmware Rg-nbs2009g-p Rg-nbs2009g-p Firmware Rg-nbs200 Firmware Rg-nbs2026g Rg-nbs2026g-p Rg-nbs2026g-p Firmware Rg-nbs2026g Firmware Rg-nbs226f Rg-nbs226f Firmware Rg-nbs228f Rg-nbs228f Firmware Rg-nbs252f Rg-nbs252f Firmware Rg-nbs3100-24gt4sfp Rg-nbs3100-24gt4sfp-p Rg-nbs3100-24gt4sfp-p Firmware Rg-nbs3100-24gt4sfp-p V2 Rg-nbs3100-24gt4sfp-p V2 Firmware Rg-nbs3100-24gt4sfp Firmware Rg-nbs3100-48gt4sfp Rg-nbs3100-48gt4sfp Firmware Rg-nbs3100-8gt2sfp Rg-nbs3100-8gt2sfp-p Rg-nbs3100-8gt2sfp-p Firmware Rg-nbs3100-8gt2sfp Firmware Rg-nbs3200-24gt4xs-p Rg-nbs3200-24gt4xs-p Firmware Rg-nbs3200-24sfp\/8gt4xs Rg-nbs3200-24sfp\/8gt4xs Firmware Rg-nbs3200-48gt4xs Rg-nbs3200-48gt4xs-p Rg-nbs3200-48gt4xs-p Firmware Rg-nbs3200-48gt4xs Firmware Rg-nbs5100-24gt4sfp Rg-nbs5100-24gt4sfp Firmware Rg-nbs5100-48gt4sfp Rg-nbs5100-48gt4sfp Firmware Rg-nbs5200-24gt4x Rg-nbs5200-24gt4x Firmware Rg-nbs5200-24sfp\/8gt4xs Rg-nbs5200-24sfp\/8gt4xs Firmware Rg-nbs5200-48gt4xs Rg-nbs5200-48gt4xs Firmware Rg-nbs5300-48mg6xs Rg-nbs5300-48mg6xs Firmware Rg-nbs5528xg Rg-nbs5528xg Firmware Rg-nbs5552xg Rg-nbs5552xg Firmware Rg-nbs5552xg V2.0 Rg-nbs5552xg V2.0 Firmware Rg-nbs5628xg Rg-nbs5628xg Firmware Rg-nbs5652xg Rg-nbs5652xg Firmware Rg-nbs5710-24gt4sfp-e Rg-nbs5710-24gt4sfp-e-p Rg-nbs5710-24gt4sfp-e-p Firmware Rg-nbs5710-24gt4sfp-e Firmware Rg-nbs5710-48gt4sfp-e Rg-nbs5710-48gt4sfp-e Firmware Rg-nbs5750-28gt4xs-e Rg-nbs5750-28gt4xs-e Firmware Rg-nbs5750v2-24gt4xs-e Rg-nbs5750v2-24gt4xs-e Firmware Rg-nbs5750v2-24sfp4xs-e Rg-nbs5750v2-24sfp4xs-e Firmware Rg-nbs5750v2-48gt4xs-e Rg-nbs5750v2-48gt4xs-e Firmware Rg-nbs5816xs Rg-nbs5816xs Firmware Rg-nbs6002 Rg-nbs6002 Firmware Rg-nbs6100-20xs4vs2qxs-s Rg-nbs6100-20xs4vs2qxs-s Firmware Rg-nbs7003 Rg-nbs7003 Firmware Rg-nbs7006 Rg-nbs7006 Firmware Rg-rap100 Rg-rap100 Firmware Rg-rap120 Rg-rap1200\(e\) Rg-rap1200\(e\) Firmware Rg-rap1200\(f\) Rg-rap1200\(f\) Firmware Rg-rap120 Firmware Rg-rap120v2 Rg-rap120v2 Firmware Rg-rap1260\(g\) Rg-rap1260\(g\) Firmware Rg-rap2200\(e\) Rg-rap2200\(e\) Firmware Rg-rap2200\(f\) Rg-rap2200\(f\) Firmware Rg-rap2200\(g\) Rg-rap2200\(g\) Firmware Rg-rap2260\(e\) Rg-rap2260\(e\) Firmware Rg-rap2260\(g\) Rg-rap2260\(g\) Firmware Rg-rap6260\(g\) Rg-rap6260\(g\) Firmware Rg-rap6261\(cd\) Rg-rap6261\(cd\) Firmware Rg-rap6261\(e\) Rg-rap6261\(e\) Firmware Rg-rap630cd Rg-rap630cd Firmware Rg-rap630ioda Rg-rap630ioda Firmware Rg-s1930 Rg-s1930-24gt4sfp Rg-s1930-24gt4sfp Firmware Rg-s1930-24t4sfp Rg-s1930-24t4sfp-p Rg-s1930-24t4sfp-p Firmware Rg-s1930-24t4sfp Firmware Rg-s1930-8gt2sfp Rg-s1930-8gt2sfp-p Rg-s1930-8gt2sfp-p Firmware Rg-s1930-8gt2sfp Firmware Rg-s1930-8t2sfp-p Rg-s1930-8t2sfp-p Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-08T14:50:58.719Z

Reserved: 2023-07-25T00:00:00.000Z

Link: CVE-2023-38902

cve-icon Vulnrichment

Updated: 2024-08-02T17:54:39.341Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T13:15:11.347

Modified: 2024-11-21T08:14:24.563

Link: CVE-2023-38902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses