CVE-2024-5337

MEDIUM

Ruijie RG-UAC <=20240516 - Code Injection

Title source: llm
STIX 2.1

Description

A vulnerability was found in Ruijie RG-UAC up to 20240516 and classified as critical. This issue affects some unknown processing of the file /view/systemConfig/sys_user/user_commit.php. The manipulation of the argument email2/user_name leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266243. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.336032
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.266243
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.266243

Scores

CVSS v3 4.7
EPSS 0.0905
EPSS Percentile 94.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (27)
ruijie/rg-uac_6000-cc_firmware
ruijie/rg-uac_6000-e10_firmware
ruijie/rg-uac_6000-e10c_firmware
ruijie/rg-uac_6000-e20_firmware
ruijie/rg-uac_6000-e20c_firmware
ruijie/rg-uac_6000-e20m_firmware
ruijie/rg-uac_6000-e50_firmware
ruijie/rg-uac_6000-e50c_firmware
ruijie/rg-uac_6000-e50m_firmware
ruijie/rg-uac_6000-ea_firmware
... and 17 more
Published May 25, 2024
Tracked Since Feb 18, 2026