Ruijie Networks Vulnerabilities and Affected Products
Vulnerabilities associated with NBR Series Routers.
Products
Clear product- Gateway EG/NBR Models1 vulnerability
- NBR Series Routers1 vulnerability
- NBR2000G/NBR1300G/NBR10001 vulnerability
- RG-UAC Application Management Gateway1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-7330CRITICAL | Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.phpRuijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation … CWE-434Nov 24, 2025 | CVSS9.3v4.0 | EPSS0.603% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |