VYPR
Vendor

Ruijie Networks

Products
288
CVEs
126
Across products
596
Status
Private

Products

288
View all 288 products →

Recent CVEs

126
View all 126 CVEs →
  • CVE-2024-24116CriOct 2, 2024
    risk 0.66cvss 9.8epss 0.28

    An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

  • CVE-2024-42936CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.01

    The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.

  • CVE-2024-52324CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.

  • CVE-2024-48874CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud…

  • CVE-2024-24117CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

  • CVE-2019-16639CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who only has web interface access) to use TELNET commands and/or show admin passwords via the mode_url=exec&command= substring. This…

  • CVE-2024-28288CriMar 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise.

  • CVE-2023-50993CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie WS6008 v1.x v2.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 and WS6108 v1.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 was discovered to contain a command injection vulnerability via the function downFiles.

  • CVE-2023-48849CriDec 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.

  • CVE-2023-34644CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.02

    Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points…

  • CVE-2023-26800CriMar 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.

  • CVE-2021-43163CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.

  • CVE-2021-43164HigMay 4, 2022
    risk 0.63cvss 8.8epss 0.35

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

  • CVE-2023-7304CriOct 15, 2025
    risk 0.61cvss epss 0.04

    Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute…

  • CVE-2025-56752CriSep 3, 2025
    risk 0.61cvss 9.4epss 0.01

    A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted…

  • CVE-2024-47547CriDec 6, 2024
    risk 0.61cvss 9.4epss 0.01

    Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.

  • CVE-2023-7330CriNov 24, 2025
    risk 0.60cvss epss 0.01

    Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation…

  • CVE-2020-36870CriNov 7, 2025
    risk 0.60cvss epss 0.01

    Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code when features such as guest…

  • CVE-2024-2909HigMar 26, 2024
    risk 0.58cvss 8.8epss 0.04

    A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the file /itbox_pi/networksafe.php?a=set of the component HTTP POST Request Handler. The manipulation of the argument bandwidth leads…

  • CVE-2025-56130HigDec 11, 2025
    risk 0.57cvss 8.8epss 0.02

    OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST request to the module_update in file /usr/local/lua/dev_config/ace_sw.lua.