CVE-2024-4255

MEDIUM

Ruijie RG-UAC <20240419 - Code Injection

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the file /view/network Config/GRE/gre_edit_commit.php. The manipulation of the argument name leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262145 was assigned to this vulnerability.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.262145
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.262145
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.319820

Scores

CVSS v3 4.7
EPSS 0.0504
EPSS Percentile 91.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (27)
ruijie/rg-uac_6000-cc_firmware
ruijie/rg-uac_6000-e10_firmware
ruijie/rg-uac_6000-e10c_firmware
ruijie/rg-uac_6000-e20_firmware
ruijie/rg-uac_6000-e20c_firmware
ruijie/rg-uac_6000-e20m_firmware
ruijie/rg-uac_6000-e50_firmware
ruijie/rg-uac_6000-e50c_firmware
ruijie/rg-uac_6000-e50m_firmware
ruijie/rg-uac_6000-ea_firmware
... and 17 more
Published Apr 27, 2024
Tracked Since Feb 18, 2026