EIP-2026-101424
PRE-CVERuijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101424. PoCs published by Riyan Firmansyah of Seclab.
AI-analyzed exploit summary This exploit demonstrates a Man-in-The-Middle (MiTM) attack against Ruijie Reyee Wireless Router firmware B11P204, leveraging unencrypted CWMP polling requests to inject arbitrary commands via a fake server. The PoC includes a custom HTTP server that intercepts device requests and responds with malicious SOAP payloads to achieve RCE.
Description
Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Exploits (1)
This exploit demonstrates a Man-in-The-Middle (MiTM) attack against Ruijie Reyee Wireless Router firmware B11P204, leveraging unencrypted CWMP polling requests to inject arbitrary commands via a fake server. The PoC includes a custom HTTP server that intercepts device requests and responds with malicious SOAP payloads to achieve RCE.