CVE-2025-34057
Ruijie NBR Router Administrative Credential Disclosure
Record summary
CVE-2025-34057 has a selected CVSS score of 8.7 (high).
Description
An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve administrative account credentials in plaintext. This flaw allows direct disclosure of sensitive user data due to improper authentication checks and insecure backend logic. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 2, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 2, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
NBR RouterBrowse Ruijie / NBR RouterDefault status: unaffected | CVE List | Version range not supplied | affected |
NBR2000G/NBR1300G/NBR1000Browse Ruijie Networks / NBR2000G/NBR1300G/NBR1000 | VulnCheck | Version data not supplied | |