CRITICAL · 9.8

CVE-2023-34644

Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series busines...

Vulnerability Description

Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
RuijieRg-Ew1200R Firmware3.0\(1\)b11p204
RuijieRg-Ew1200R-
RuijieRg-Ew300 Firmware3.0\(1\)b11p204
RuijieRg-Ew300-
RuijieRg-Ew3200Gx Firmware3.0\(1\)b11p204
RuijieRg-Ew3200Gx-
RuijieRg-Ew1200G Firmware3.0\(1\)b11p204
RuijieRg-Ew1200G-
RuijieRg-Ew1800Gx Firmware3.0\(1\)b11p204
RuijieRg-Ew1800Gx-
RuijieRg-Ew300R Firmware3.0\(1\)b11p204
RuijieRg-Ew300R-
RuijieRg-Ew1200 Firmware3.0\(1\)b11p204
RuijieRg-Ew1200-
RuijieRg-Eg3000Xe Firmware3.0\(1\)b11p216
RuijieRg-Eg3000Xe-
RuijieRg-Eg105G Firmware3.0\(1\)b11p216
RuijieRg-Eg105G-
RuijieRg-Eg305Gh-P-E Firmware3.0\(1\)b11p216
RuijieRg-Eg305Gh-P-E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-34644?

CVE-2023-34644 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series busines...

How severe is CVE-2023-34644?

CVE-2023-34644 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-34644?

Check the references section above for vendor advisories and patch information. Affected products include: Ruijie Rg-Ew1200R Firmware, Ruijie Rg-Ew1200R, Ruijie Rg-Ew300 Firmware, Ruijie Rg-Ew300, Ruijie Rg-Ew3200Gx Firmware.