Description
A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
Published: 2023-08-17
Score: 8.8 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-42663 A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
History

Tue, 08 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijie nbc Series Wireless Controllers
Ruijie rg-eg
Ruijie rg-ew
Ruijie rg-ew Series Routers And Repeaters
Ruijie rg-s1930
CPEs cpe:2.3:h:ruijie:nbc_series_wireless_controllers:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-ew:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-ew_series_routers_and_repeaters:*:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-s1930:*:*:*:*:*:*:*:*
Vendors & Products Ruijie nbc Series Wireless Controllers
Ruijie rg-eg
Ruijie rg-ew
Ruijie rg-ew Series Routers And Repeaters
Ruijie rg-s1930
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ruijie Nbc Series Wireless Controllers Rg-eap101 Rg-eap101 Firmware Rg-eap101 V2 Rg-eap101 V2 Firmware Rg-eap102 Rg-eap102\(f\) Rg-eap102\(f\) Firmware Rg-eap102 Firmware Rg-eap102 V2 Rg-eap102 V2 Firmware Rg-eap162\(g\) Rg-eap162\(g\) Firmware Rg-eap201 Rg-eap201 Firmware Rg-eap202 Rg-eap202 Firmware Rg-eap212\(f\) Rg-eap212\(f\) Firmware Rg-eap212\(g\) Rg-eap212\(g\) Firmware Rg-eap262\(g\) Rg-eap262\(g\) Firmware Rg-eap602 Rg-eap602 Firmware Rg-eap662\(g\) Rg-eap662\(g\) Firmware Rg-eg Rg-eg105g-e Rg-eg105g-e Firmware Rg-eg105g-pe Rg-eg105g-pe Firmware Rg-eg105g V2 Rg-eg105g V2 Firmware Rg-eg210g-e Rg-eg210g-e Firmware Rg-eg210g-p Rg-eg210g-p Firmware Rg-eg210g-pe Rg-eg210g-pe Firmware Rg-ew Rg-ew1200 Rg-ew1200 Firmware Rg-ew1200g Pro Rg-ew1200g Pro Firmware Rg-ew1200r Rg-ew1200r Firmware Rg-ew1300g Rg-ew1300g Firmware Rg-ew1800gx Pro Rg-ew1800gx Pro Firmware Rg-ew3000gx Pro Rg-ew3000gx Pro Firmware Rg-ew300 Pro Rg-ew300 Pro Firmware Rg-ew300r Rg-ew300r Firmware Rg-ew3200gx Pro Rg-ew3200gx Pro Firmware Rg-ew Series Routers And Repeaters Rg-nb3200-24gt4xs Rg-nb3200-24gt4xs Firmware Rg-nbc256 Rg-nbc256 Firmware Rg-nbc512 Rg-nbc512 Firmware Rg-nbs1850gc Rg-nbs1850gc Firmware Rg-nbs1850gc V2 Rg-nbs1850gc V2 Firmware Rg-nbs200 Rg-nbs2000 Rg-nbs2000 Firmware Rg-nbs2009g-p Rg-nbs2009g-p Firmware Rg-nbs200 Firmware Rg-nbs2026g Rg-nbs2026g-p Rg-nbs2026g-p Firmware Rg-nbs2026g Firmware Rg-nbs226f Rg-nbs226f Firmware Rg-nbs228f Rg-nbs228f Firmware Rg-nbs252f Rg-nbs252f Firmware Rg-nbs3100-24gt4sfp Rg-nbs3100-24gt4sfp-p Rg-nbs3100-24gt4sfp-p Firmware Rg-nbs3100-24gt4sfp-p V2 Rg-nbs3100-24gt4sfp-p V2 Firmware Rg-nbs3100-24gt4sfp Firmware Rg-nbs3100-48gt4sfp Rg-nbs3100-48gt4sfp Firmware Rg-nbs3100-8gt2sfp Rg-nbs3100-8gt2sfp-p Rg-nbs3100-8gt2sfp-p Firmware Rg-nbs3100-8gt2sfp Firmware Rg-nbs3200-24gt4xs-p Rg-nbs3200-24gt4xs-p Firmware Rg-nbs3200-24sfp\/8gt4xs Rg-nbs3200-24sfp\/8gt4xs Firmware Rg-nbs3200-48gt4xs Rg-nbs3200-48gt4xs-p Rg-nbs3200-48gt4xs-p Firmware Rg-nbs3200-48gt4xs Firmware Rg-nbs5100-24gt4sfp Rg-nbs5100-24gt4sfp Firmware Rg-nbs5100-48gt4sfp Rg-nbs5100-48gt4sfp Firmware Rg-nbs5200-24gt4x Rg-nbs5200-24gt4x Firmware Rg-nbs5200-24sfp\/8gt4xs Rg-nbs5200-24sfp\/8gt4xs Firmware Rg-nbs5200-48gt4xs Rg-nbs5200-48gt4xs Firmware Rg-nbs5300-48mg6xs Rg-nbs5300-48mg6xs Firmware Rg-nbs5528xg Rg-nbs5528xg Firmware Rg-nbs5552xg Rg-nbs5552xg Firmware Rg-nbs5552xg V2.0 Rg-nbs5552xg V2.0 Firmware Rg-nbs5628xg Rg-nbs5628xg Firmware Rg-nbs5652xg Rg-nbs5652xg Firmware Rg-nbs5710-24gt4sfp-e Rg-nbs5710-24gt4sfp-e-p Rg-nbs5710-24gt4sfp-e-p Firmware Rg-nbs5710-24gt4sfp-e Firmware Rg-nbs5710-48gt4sfp-e Rg-nbs5710-48gt4sfp-e Firmware Rg-nbs5750-28gt4xs-e Rg-nbs5750-28gt4xs-e Firmware Rg-nbs5750v2-24gt4xs-e Rg-nbs5750v2-24gt4xs-e Firmware Rg-nbs5750v2-24sfp4xs-e Rg-nbs5750v2-24sfp4xs-e Firmware Rg-nbs5750v2-48gt4xs-e Rg-nbs5750v2-48gt4xs-e Firmware Rg-nbs5816xs Rg-nbs5816xs Firmware Rg-nbs6002 Rg-nbs6002 Firmware Rg-nbs6100-20xs4vs2qxs-s Rg-nbs6100-20xs4vs2qxs-s Firmware Rg-nbs7003 Rg-nbs7003 Firmware Rg-nbs7006 Rg-nbs7006 Firmware Rg-rap100 Rg-rap100 Firmware Rg-rap120 Rg-rap1200\(e\) Rg-rap1200\(e\) Firmware Rg-rap1200\(f\) Rg-rap1200\(f\) Firmware Rg-rap120 Firmware Rg-rap120v2 Rg-rap120v2 Firmware Rg-rap1260\(g\) Rg-rap1260\(g\) Firmware Rg-rap2200\(e\) Rg-rap2200\(e\) Firmware Rg-rap2200\(f\) Rg-rap2200\(f\) Firmware Rg-rap2200\(g\) Rg-rap2200\(g\) Firmware Rg-rap2260\(e\) Rg-rap2260\(e\) Firmware Rg-rap2260\(g\) Rg-rap2260\(g\) Firmware Rg-rap6260\(g\) Rg-rap6260\(g\) Firmware Rg-rap6261\(cd\) Rg-rap6261\(cd\) Firmware Rg-rap6261\(e\) Rg-rap6261\(e\) Firmware Rg-rap630cd Rg-rap630cd Firmware Rg-rap630ioda Rg-rap630ioda Firmware Rg-s1930 Rg-s1930-24gt4sfp Rg-s1930-24gt4sfp Firmware Rg-s1930-24t4sfp Rg-s1930-24t4sfp-p Rg-s1930-24t4sfp-p Firmware Rg-s1930-24t4sfp Firmware Rg-s1930-8gt2sfp Rg-s1930-8gt2sfp-p Rg-s1930-8gt2sfp-p Firmware Rg-s1930-8gt2sfp Firmware Rg-s1930-8t2sfp-p Rg-s1930-8t2sfp-p Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-08T14:50:58.719Z

Reserved: 2023-07-25T00:00:00.000Z

Link: CVE-2023-38902

cve-icon Vulnrichment

Updated: 2024-08-02T17:54:39.341Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T13:15:11.347

Modified: 2024-11-21T08:14:24.563

Link: CVE-2023-38902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses