CVE-2021-43160: Command Injection
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43160?
CVE-2021-43160 is classified as a Remote Code Execution (RCE) vulnerability which has a critical severity level.
How do I fix CVE-2021-43160?
To mitigate CVE-2021-43160, upgrade the affected Ruijie Networks Ruijie RG-EW Series Routers firmware to version 1.55.1916 or later.
Which devices are affected by CVE-2021-43160?
CVE-2021-43160 affects Ruijie Networks RG-EW Series Routers running ReyeeOS versions up to 1.55.1915 / EW_3.0(1)B11P55.
What is the impact of CVE-2021-43160?
The impact of CVE-2021-43160 allows an attacker to execute arbitrary code on the impacted devices remotely.
Is there a workaround for CVE-2021-43160 if an upgrade is not possible?
Currently, there are no known workarounds for CVE-2021-43160 other than applying the necessary firmware update.