Showing 1 vulnerability on this page for NBR Series Routers

Signals CISA KEV Ransomware Nuclei
Ruijie Networks vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php

Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation

CWE-434Nov 24, 2025
CVSS9.3v4.0EPSS0.603%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX