漏洞描述
A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2023-4415↗github.comhttps://github.com/blakespire/repoforcve/tree/main/RG-EW1200G-logic↗vuldb.comhttps://vuldb.com/?ctiid.237518↗vuldb.comhttps://vuldb.com/?id.237518↗github.comhttps://github.com/thedarknessdied/Ruijie_RG-EW1200G_login_bypass-CVE-2023-4415↗