Vulnerability Description
RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_alarmAction at /alarm_pi/alarmService.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruijienetworks | Rg-Eg350 Firmware | eg_rgos_11.1\(6\) |
| Ruijienetworks | Rg-Eg350 | 1.0 |
Related Weaknesses (CWE)
References
- http://blog.mo60.cn/index.php/archives/ruijie.htmlNot Applicable
- http://blog.mo60.cn/index.php/archives/ruijie.htmlNot Applicable
FAQ
What is CVE-2022-33128?
CVE-2022-33128 is a vulnerability with a CVSS score of 9.1 (CRITICAL). RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_alarmAction at /alarm_pi/alarmService.php.
How severe is CVE-2022-33128?
CVE-2022-33128 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-33128?
Check the references section above for vendor advisories and patch information. Affected products include: Ruijienetworks Rg-Eg350 Firmware, Ruijienetworks Rg-Eg350.