Beijing Star-Net Ruijie Network Technology Co., Ltd. Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Beijing Star-Net Ruijie Network Technology Co., Ltd. products.
Products
- EG32101 vulnerability
- EG32201 vulnerability
- EG32301 vulnerability
- EG32501 vulnerability
- NBR Series Routers1 vulnerability
- NBR1000G-C1 vulnerability
- NBR1000G-E1 vulnerability
- NBR108G-P1 vulnerability
- NBR1300G-E1 vulnerability
- NBR1700G-E1 vulnerability
- NBR2000G-C1 vulnerability
- NBR2100G-E1 vulnerability
- NBR2500D-E1 vulnerability
- NBR3000D-E1 vulnerability
- NBR3000G-S1 vulnerability
- NBR6120-E1 vulnerability
- NBR6135-E1 vulnerability
- NBR6205-E1 vulnerability
- NBR6210-E1 vulnerability
- NBR6215-E1 vulnerability
- NBR800G1 vulnerability
- NBR950G1 vulnerability
- RG-EG1000C1 vulnerability
- RG-EG2000CE1 vulnerability
- RG-EG2000F1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-7330CRITICAL | Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.phpRuijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation … CWE-434Nov 24, 2025 | CVSS9.3v4.0 | EPSS0.603% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36870CRITICAL | Ruijie Gateway EG & NBR Models v11.1(6)B9P1 - 11.9(4)B12P1 RCEVarious Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code when features such as guest authentication, local server authentication, or screen mirroring are enabled to gain access or execute commands on affected devices. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-05 UTC. CWE-94Nov 7, 2025 | CVSS9.2v4.0 | EPSS0.753% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |