CVE-2023-26800: Command Injection
Published Mar 26, 2023
·Updated
Ruijie Networks RG-EW1200 Wireless Routers EW3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.
Affected Software
6 affected components
Ruijienetworks Rg-ew1200r Firmware=ew_3.0\(1\)b11p204
Ruijienetworks Rg-ew1200r
Ruijienetworks Rg-ew1200 Firmware=ew_3.0\(1\)b11p204
Ruijienetworks Rg-ew1200
Ruijienetworks Rg-ew1200g Pro Firmware=ew_3.0\(1\)b11p204
Ruijienetworks Rg-ew1200g Pro
Event History
Mar 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-26800?
CVE-2023-26800 is a command injection vulnerability in Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204.
2
How severe is CVE-2023-26800?
CVE-2023-26800 has a severity score of 9.8, which is considered critical.
3
How does CVE-2023-26800 affect Ruijie Networks RG-EW1200 Wireless Routers?
CVE-2023-26800 affects Ruijie Networks RG-EW1200 Wireless Routers running the EW_3.0(1)B11P204 firmware version.
4
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2023-26800.
5
Is Ruijie Networks RG-EW1200 Wireless Router vulnerable to CVE-2023-26800?
Yes, Ruijie Networks RG-EW1200 Wireless Router with the EW_3.0(1)B11P204 firmware version is vulnerable to CVE-2023-26800.