CVE-2021-43164
🟠 Łataj w tym tygodniu
Wykonanie zdalnego kodu w routerach Ruijie RG-EW umożliwia nieautoryzowany dostęp.
CVSS
8.8
EPSS
34.0%
Exploit
poc
Vendor
ruijienetworks
Opis źródłowy (NVD)
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.
exploit rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 34.0% |
| Opublikowano (NVD) | 2022-05-04 01:15:49 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-09 01:17:08 UTC |
Referencje
- http://packetstormsecurity.com/files/167099/Ruijie-Reyee-Mesh-Router-Remote-Code-Execution.html (cve@mitre.org) [Exploit, Third Party Advisory, VDB Entry]
- https://seclists.org/fulldisclosure/2022/May/0 (cve@mitre.org) [Mailing List, Third Party Advisory]