Vulnerability Description
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruijienetworks | Reyeeos | <= 1.55.1915_ew_3.0\(1\)b11p55 |
| Ruijienetworks | Rg-Ew1200 | - |
| Ruijienetworks | Rg-Ew1200G Pro | - |
| Ruijienetworks | Rg-Ew1800Gx Pro | - |
| Ruijienetworks | Rg-Ew300 Pro | - |
| Ruijienetworks | Rg-Ew3200Gx Pro | - |
Related Weaknesses (CWE)
References
- http://ruijie.comNot Applicable
- https://seclists.org/fulldisclosure/2022/May/0Mailing ListThird Party Advisory
- http://ruijie.comNot Applicable
- https://seclists.org/fulldisclosure/2022/May/0Mailing ListThird Party Advisory
FAQ
What is CVE-2021-43163?
CVE-2021-43163 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
How severe is CVE-2021-43163?
CVE-2021-43163 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-43163?
Check the references section above for vendor advisories and patch information. Affected products include: Ruijienetworks Reyeeos, Ruijienetworks Rg-Ew1200, Ruijienetworks Rg-Ew1200G Pro, Ruijienetworks Rg-Ew1800Gx Pro, Ruijienetworks Rg-Ew300 Pro.