CVE-2023-53881

HIGH

ReyeeOS 1.204.1614 - Man-In-The-Middle

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53881. PoCs published by Riyan Firmansyah of Seclab.

AI-analyzed exploit summary This exploit demonstrates a Man-in-The-Middle (MiTM) attack against Ruijie ReyeeOS devices by impersonating a CWMP server to execute arbitrary commands via OS command injection in diagnostic tools. It sets up a fake HTTP server to intercept and respond to CWMP requests, enabling remote code execution.

Description

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.

Exploits (1)

exploitdb WORKING POC
by Riyan Firmansyah of Seclab · pythonremotehardware
https://www.exploit-db.com/exploits/51642

This exploit demonstrates a Man-in-The-Middle (MiTM) attack against Ruijie ReyeeOS devices by impersonating a CWMP server to execute arbitrary commands via OS command injection in diagnostic tools. It sets up a fake HTTP server to intercept and respond to CWMP requests, enabling remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ruijie ReyeeOS 1.204.1614; EW_3.0(1)B11P204, Release(10161400)
No auth needed
Prerequisites: Network access to intercept CWMP traffic · Victim device must initiate CWMP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Product, Broken Link product
https://ruijienetworks.com

Scores

CVSS v3 8.1
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-319
Status published
Products (2)
Ruijie/ReyeeOS 1.204.1614
ruijienetworks/reyee_os 1.204.1614
Published Dec 15, 2025
Tracked Since Feb 18, 2026