CVE-2019-16639: OS Command Injection
An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who only has web interface access) to use TELNET commands and/or show admin passwords via the modeurl=exec&command= substring. This affects EG-2000SE EGRGOS 11.9 B11P1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16639?
CVE-2019-16639 has been classified as a critical vulnerability due to the lack of access control in the API interface.
How do I fix CVE-2019-16639?
To fix CVE-2019-16639, implement strict access controls on the newcli.php API interface to prevent unauthorized access.
What are the potential impacts of CVE-2019-16639?
The potential impacts of CVE-2019-16639 include unauthorized execution of TELNET commands and exposure of admin passwords.
Which devices are affected by CVE-2019-16639?
CVE-2019-16639 specifically affects the Ruijie EG-2000SE series gateway.
Can CVE-2019-16639 be exploited remotely?
Yes, CVE-2019-16639 can be exploited by an attacker who has access to the web interface.