CVE-2021-43162: Command Injection
Published May 4, 2022
·Updated
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.
Affected Software
12 affected components
Ruijienetworks Reyeeos<=1.55.1915_ew_3.0\(1\)b11p55
Ruijienetworks Rg-ew1200
Ruijienetworks Rg-ew1200g Pro
Ruijienetworks Rg-ew1800gx Pro
Ruijienetworks Rg-ew300 Pro
Ruijienetworks Rg-ew3200gx Pro
All of the following
Ruijienetworks Reyeeos<=1.55.1915_ew_3.0\(1\)b11p55
Any of the following
Ruijienetworks Rg-ew1200
Ruijienetworks Rg-ew1200g Pro
Ruijienetworks Rg-ew1800gx Pro
Ruijienetworks Rg-ew300 Pro
Ruijienetworks Rg-ew3200gx Pro
Event History
May 4, 2022
CVE Published
via MITRE·12:08 AM
Data Sourced
via MITRE·12:08 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-43162?
CVE-2021-43162 is a Remote Code Execution (RCE) vulnerability that exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.
2
What is the severity of CVE-2021-43162?
CVE-2021-43162 has a severity level of 8.8 (high).
3
Which software versions are affected by CVE-2021-43162?
CVE-2021-43162 affects Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55.
4
How can I fix CVE-2021-43162?
To fix CVE-2021-43162, users should update their Ruijie RG-EW Series Routers to a version that includes the fix for this vulnerability.