A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.

Project Subscriptions

Vendors Products
Nbc Series Wireless Controllers Subscribe
Rg-eap101 Subscribe
Rg-eap101 Firmware Subscribe
Rg-eap101 V2 Subscribe
Rg-eap101 V2 Firmware Subscribe
Rg-eap102 Subscribe
Rg-eap102\(f\) Subscribe
Rg-eap102\(f\) Firmware Subscribe
Rg-eap102 Firmware Subscribe
Rg-eap102 V2 Subscribe
Rg-eap102 V2 Firmware Subscribe
Rg-eap162\(g\) Subscribe
Rg-eap162\(g\) Firmware Subscribe
Rg-eap201 Subscribe
Rg-eap201 Firmware Subscribe
Rg-eap202 Subscribe
Rg-eap202 Firmware Subscribe
Rg-eap212\(f\) Subscribe
Rg-eap212\(f\) Firmware Subscribe
Rg-eap212\(g\) Subscribe
Rg-eap212\(g\) Firmware Subscribe
Rg-eap262\(g\) Subscribe
Rg-eap262\(g\) Firmware Subscribe
Rg-eap602 Subscribe
Rg-eap602 Firmware Subscribe
Rg-eap662\(g\) Subscribe
Rg-eap662\(g\) Firmware Subscribe
Rg-eg105g-e Subscribe
Rg-eg105g-e Firmware Subscribe
Rg-eg105g-pe Subscribe
Rg-eg105g-pe Firmware Subscribe
Rg-eg105g V2 Subscribe
Rg-eg105g V2 Firmware Subscribe
Rg-eg210g-e Subscribe
Rg-eg210g-e Firmware Subscribe
Rg-eg210g-p Subscribe
Rg-eg210g-p Firmware Subscribe
Rg-eg210g-pe Subscribe
Rg-eg210g-pe Firmware Subscribe
Rg-ew1200 Subscribe
Rg-ew1200 Firmware Subscribe
Rg-ew1200g Pro Subscribe
Rg-ew1200g Pro Firmware Subscribe
Rg-ew1200r Subscribe
Rg-ew1200r Firmware Subscribe
Rg-ew1300g Subscribe
Rg-ew1300g Firmware Subscribe
Rg-ew1800gx Pro Subscribe
Rg-ew1800gx Pro Firmware Subscribe
Rg-ew3000gx Pro Subscribe
Rg-ew3000gx Pro Firmware Subscribe
Rg-ew300 Pro Subscribe
Rg-ew300 Pro Firmware Subscribe
Rg-ew300r Subscribe
Rg-ew300r Firmware Subscribe
Rg-ew3200gx Pro Subscribe
Rg-ew3200gx Pro Firmware Subscribe
Rg-ew Series Routers And Repeaters Subscribe
Rg-nb3200-24gt4xs Subscribe
Rg-nb3200-24gt4xs Firmware Subscribe
Rg-nbc256 Subscribe
Rg-nbc256 Firmware Subscribe
Rg-nbc512 Subscribe
Rg-nbc512 Firmware Subscribe
Rg-nbs1850gc Subscribe
Rg-nbs1850gc Firmware Subscribe
Rg-nbs1850gc V2 Subscribe
Rg-nbs1850gc V2 Firmware Subscribe
Rg-nbs200 Subscribe
Rg-nbs2000 Subscribe
Rg-nbs2000 Firmware Subscribe
Rg-nbs2009g-p Subscribe
Rg-nbs2009g-p Firmware Subscribe
Rg-nbs200 Firmware Subscribe
Rg-nbs2026g Subscribe
Rg-nbs2026g-p Subscribe
Rg-nbs2026g-p Firmware Subscribe
Rg-nbs2026g Firmware Subscribe
Rg-nbs226f Subscribe
Rg-nbs226f Firmware Subscribe
Rg-nbs228f Subscribe
Rg-nbs228f Firmware Subscribe
Rg-nbs252f Subscribe
Rg-nbs252f Firmware Subscribe
Rg-nbs3100-24gt4sfp Subscribe
Rg-nbs3100-24gt4sfp-p Subscribe
Rg-nbs3100-24gt4sfp-p Firmware Subscribe
Rg-nbs3100-24gt4sfp-p V2 Subscribe
Rg-nbs3100-24gt4sfp-p V2 Firmware Subscribe
Rg-nbs3100-24gt4sfp Firmware Subscribe
Rg-nbs3100-48gt4sfp Subscribe
Rg-nbs3100-48gt4sfp Firmware Subscribe
Rg-nbs3100-8gt2sfp Subscribe
Rg-nbs3100-8gt2sfp-p Subscribe
Rg-nbs3100-8gt2sfp-p Firmware Subscribe
Rg-nbs3100-8gt2sfp Firmware Subscribe
Rg-nbs3200-24gt4xs-p Subscribe
Rg-nbs3200-24gt4xs-p Firmware Subscribe
Rg-nbs3200-24sfp\/8gt4xs Subscribe
Rg-nbs3200-24sfp\/8gt4xs Firmware Subscribe
Rg-nbs3200-48gt4xs Subscribe
Rg-nbs3200-48gt4xs-p Subscribe
Rg-nbs3200-48gt4xs-p Firmware Subscribe
Rg-nbs3200-48gt4xs Firmware Subscribe
Rg-nbs5100-24gt4sfp Subscribe
Rg-nbs5100-24gt4sfp Firmware Subscribe
Rg-nbs5100-48gt4sfp Subscribe
Rg-nbs5100-48gt4sfp Firmware Subscribe
Rg-nbs5200-24gt4x Subscribe
Rg-nbs5200-24gt4x Firmware Subscribe
Rg-nbs5200-24sfp\/8gt4xs Subscribe
Rg-nbs5200-24sfp\/8gt4xs Firmware Subscribe
Rg-nbs5200-48gt4xs Subscribe
Rg-nbs5200-48gt4xs Firmware Subscribe
Rg-nbs5300-48mg6xs Subscribe
Rg-nbs5300-48mg6xs Firmware Subscribe
Rg-nbs5528xg Subscribe
Rg-nbs5528xg Firmware Subscribe
Rg-nbs5552xg Subscribe
Rg-nbs5552xg Firmware Subscribe
Rg-nbs5552xg V2.0 Subscribe
Rg-nbs5552xg V2.0 Firmware Subscribe
Rg-nbs5628xg Subscribe
Rg-nbs5628xg Firmware Subscribe
Rg-nbs5652xg Subscribe
Rg-nbs5652xg Firmware Subscribe
Rg-nbs5710-24gt4sfp-e Subscribe
Rg-nbs5710-24gt4sfp-e-p Subscribe
Rg-nbs5710-24gt4sfp-e-p Firmware Subscribe
Rg-nbs5710-24gt4sfp-e Firmware Subscribe
Rg-nbs5710-48gt4sfp-e Subscribe
Rg-nbs5710-48gt4sfp-e Firmware Subscribe
Rg-nbs5750-28gt4xs-e Subscribe
Rg-nbs5750-28gt4xs-e Firmware Subscribe
Rg-nbs5750v2-24gt4xs-e Subscribe
Rg-nbs5750v2-24gt4xs-e Firmware Subscribe
Rg-nbs5750v2-24sfp4xs-e Subscribe
Rg-nbs5750v2-24sfp4xs-e Firmware Subscribe
Rg-nbs5750v2-48gt4xs-e Subscribe
Rg-nbs5750v2-48gt4xs-e Firmware Subscribe
Rg-nbs5816xs Subscribe
Rg-nbs5816xs Firmware Subscribe
Rg-nbs6002 Subscribe
Rg-nbs6002 Firmware Subscribe
Rg-nbs6100-20xs4vs2qxs-s Subscribe
Rg-nbs6100-20xs4vs2qxs-s Firmware Subscribe
Rg-nbs7003 Subscribe
Rg-nbs7003 Firmware Subscribe
Rg-nbs7006 Subscribe
Rg-nbs7006 Firmware Subscribe
Rg-rap100 Subscribe
Rg-rap100 Firmware Subscribe
Rg-rap120 Subscribe
Rg-rap1200\(e\) Subscribe
Rg-rap1200\(e\) Firmware Subscribe
Rg-rap1200\(f\) Subscribe
Rg-rap1200\(f\) Firmware Subscribe
Rg-rap120 Firmware Subscribe
Rg-rap120v2 Subscribe
Rg-rap120v2 Firmware Subscribe
Rg-rap1260\(g\) Subscribe
Rg-rap1260\(g\) Firmware Subscribe
Rg-rap2200\(e\) Subscribe
Rg-rap2200\(e\) Firmware Subscribe
Rg-rap2200\(f\) Subscribe
Rg-rap2200\(f\) Firmware Subscribe
Rg-rap2200\(g\) Subscribe
Rg-rap2200\(g\) Firmware Subscribe
Rg-rap2260\(e\) Subscribe
Rg-rap2260\(e\) Firmware Subscribe
Rg-rap2260\(g\) Subscribe
Rg-rap2260\(g\) Firmware Subscribe
Rg-rap6260\(g\) Subscribe
Rg-rap6260\(g\) Firmware Subscribe
Rg-rap6261\(cd\) Subscribe
Rg-rap6261\(cd\) Firmware Subscribe
Rg-rap6261\(e\) Subscribe
Rg-rap6261\(e\) Firmware Subscribe
Rg-rap630cd Subscribe
Rg-rap630cd Firmware Subscribe
Rg-rap630ioda Subscribe
Rg-rap630ioda Firmware Subscribe
Rg-s1930 Subscribe
Rg-s1930-24gt4sfp Subscribe
Rg-s1930-24gt4sfp Firmware Subscribe
Rg-s1930-24t4sfp Subscribe
Rg-s1930-24t4sfp-p Subscribe
Rg-s1930-24t4sfp-p Firmware Subscribe
Rg-s1930-24t4sfp Firmware Subscribe
Rg-s1930-8gt2sfp Subscribe
Rg-s1930-8gt2sfp-p Subscribe
Rg-s1930-8gt2sfp-p Firmware Subscribe
Rg-s1930-8gt2sfp Firmware Subscribe
Rg-s1930-8t2sfp-p Subscribe
Rg-s1930-8t2sfp-p Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-42663 A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 08 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijie nbc Series Wireless Controllers
Ruijie rg-eg
Ruijie rg-ew
Ruijie rg-ew Series Routers And Repeaters
Ruijie rg-s1930
CPEs cpe:2.3:h:ruijie:nbc_series_wireless_controllers:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-ew:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-ew_series_routers_and_repeaters:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-s1930:*:*:*:*:*:*:*:*
Vendors & Products Ruijie nbc Series Wireless Controllers
Ruijie rg-eg
Ruijie rg-ew
Ruijie rg-ew Series Routers And Repeaters
Ruijie rg-s1930
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-08T14:50:58.719Z

Reserved: 2023-07-25T00:00:00

Link: CVE-2023-38902

cve-icon Vulnrichment

Updated: 2024-08-02T17:54:39.341Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T13:15:11.347

Modified: 2024-11-21T08:14:24.563

Link: CVE-2023-38902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses