Vulnerability Description
Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruijienetworks | Rg-Ew1200R Firmware | ew_3.0\(1\)b11p204 |
| Ruijienetworks | Rg-Ew1200R | - |
| Ruijienetworks | Rg-Ew1200 Firmware | ew_3.0\(1\)b11p204 |
| Ruijienetworks | Rg-Ew1200 | - |
| Ruijienetworks | Rg-Ew1200G Pro Firmware | ew_3.0\(1\)b11p204 |
| Ruijienetworks | Rg-Ew1200G Pro | - |
Related Weaknesses (CWE)
References
- https://github.com/winmt/my-vuls/tree/main/RG-EW1200ExploitThird Party Advisory
- https://github.com/winmt/my-vuls/tree/main/RG-EW1200ExploitThird Party Advisory
FAQ
What is CVE-2023-26800?
CVE-2023-26800 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.
How severe is CVE-2023-26800?
CVE-2023-26800 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-26800?
Check the references section above for vendor advisories and patch information. Affected products include: Ruijienetworks Rg-Ew1200R Firmware, Ruijienetworks Rg-Ew1200R, Ruijienetworks Rg-Ew1200 Firmware, Ruijienetworks Rg-Ew1200, Ruijienetworks Rg-Ew1200G Pro Firmware.