Vulnerability Description
Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruijie | Rg-Ew1200R Firmware | 3.0\(1\)b11p204 |
| Ruijie | Rg-Ew1200R | - |
| Ruijie | Rg-Ew300 Firmware | 3.0\(1\)b11p204 |
| Ruijie | Rg-Ew300 | - |
| Ruijie | Rg-Ew3200Gx Firmware | 3.0\(1\)b11p204 |
| Ruijie | Rg-Ew3200Gx | - |
| Ruijie | Rg-Ew1200G Firmware | 3.0\(1\)b11p204 |
| Ruijie | Rg-Ew1200G | - |
| Ruijie | Rg-Ew1800Gx Firmware | 3.0\(1\)b11p204 |
| Ruijie | Rg-Ew1800Gx | - |
| Ruijie | Rg-Ew300R Firmware | 3.0\(1\)b11p204 |
| Ruijie | Rg-Ew300R | - |
| Ruijie | Rg-Ew1200 Firmware | 3.0\(1\)b11p204 |
| Ruijie | Rg-Ew1200 | - |
| Ruijie | Rg-Eg3000Xe Firmware | 3.0\(1\)b11p216 |
| Ruijie | Rg-Eg3000Xe | - |
| Ruijie | Rg-Eg105G Firmware | 3.0\(1\)b11p216 |
| Ruijie | Rg-Eg105G | - |
| Ruijie | Rg-Eg305Gh-P-E Firmware | 3.0\(1\)b11p216 |
| Ruijie | Rg-Eg305Gh-P-E | - |
Related Weaknesses (CWE)
References
- https://www.ruijie.com.cn/gy/xw-aqtg-gw/91389/PatchVendor Advisory
- https://www.ruijienetworks.com/support/securityBulletins/cybersecurity_bulletins
- https://www.ruijie.com.cn/gy/xw-aqtg-gw/91389/PatchVendor Advisory
- https://www.ruijienetworks.com/support/securityBulletins/cybersecurity_bulletins
FAQ
What is CVE-2023-34644?
CVE-2023-34644 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series busines...
How severe is CVE-2023-34644?
CVE-2023-34644 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-34644?
Check the references section above for vendor advisories and patch information. Affected products include: Ruijie Rg-Ew1200R Firmware, Ruijie Rg-Ew1200R, Ruijie Rg-Ew300 Firmware, Ruijie Rg-Ew300, Ruijie Rg-Ew3200Gx Firmware.