Impact
The flaw resides in Ruijie RG‑UAC firmware’s user_auth_commit.php and allows a remote caller to manipulate the upload_image parameter, resulting in an unrestricted upload of arbitrary files. This weakness combines issues of incomplete access control (CWE‑284) and missing file type validation (CWE‑434), allowing an attacker to place malicious files on the device. If the uploaded file can be executed, the vulnerability could lead to arbitrary code execution or lateral movement within the network.
Affected Systems
All Ruijie RG‑UAC devices running firmware versions up to 1.0‑R1.8.2.p5 are affected; the vulnerability applies regardless of specific model or configuration, as the exposed function exists in the stated firmware snapshot.
Risk and Exploitability
With a CVSS score of 6.9, the flaw is of moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not yet listed in the CISA KEV catalogue. Nonetheless, the public, remote exploitability means operators should treat this as a moderate to high risk contingent on the presence of additional safeguards, as an attacker could upload and potentially execute files after compromise.
OpenCVE Enrichment