CVE-2021-43163: Command Injection
Published May 4, 2022
·Updated
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
Affected Software
12 affected components
Ruijienetworks Reyeeos<=1.55.1915_ew_3.0\(1\)b11p55
Ruijienetworks Rg-ew1200
Ruijienetworks Rg-ew1200g Pro
Ruijienetworks Rg-ew1800gx Pro
Ruijienetworks Rg-ew300 Pro
Ruijienetworks Rg-ew3200gx Pro
All of the following
Ruijienetworks Reyeeos<=1.55.1915_ew_3.0\(1\)b11p55
Any of the following
Ruijienetworks Rg-ew1200
Ruijienetworks Rg-ew1200g Pro
Ruijienetworks Rg-ew1800gx Pro
Ruijienetworks Rg-ew300 Pro
Ruijienetworks Rg-ew3200gx Pro
Event History
May 4, 2022
CVE Published
via MITRE·12:08 AM
Data Sourced
via MITRE·12:08 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43163?
CVE-2021-43163 is classified as a critical severity vulnerability that can lead to remote code execution.
2
How do I fix CVE-2021-43163?
To mitigate CVE-2021-43163, update the affected Ruijie RG-EW Series Routers to ReyeeOS version 1.55.1916 or later.
3
What systems are affected by CVE-2021-43163?
CVE-2021-43163 affects Ruijie RG-EW Series Routers running ReyeeOS up to version 1.55.1915.
4
What type of vulnerability is CVE-2021-43163?
CVE-2021-43163 is a Remote Code Execution (RCE) vulnerability that allows an attacker to execute arbitrary code remotely.
5
Is there a known exploit for CVE-2021-43163?
Yes, CVE-2021-43163 has been identified as exploitable, allowing attackers to target vulnerable routers.