CVE-2024-2909: Ruijie RG-EG350 HTTP POST Request setAction os command injection
A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the file /itboxpi/networksafe.php?a=set of the component HTTP POST Request Handler. The manipulation of the argument bandwidth leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257977 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2909?
CVE-2024-2909 is classified as a critical vulnerability.
How do I fix CVE-2024-2909?
To fix CVE-2024-2909, update the Ruijie RG-EG350 device to a version released after 20240318.
What component is affected by CVE-2024-2909?
CVE-2024-2909 affects the HTTP POST Request Handler in the Ruijie RG-EG350 device.
What is the root cause of CVE-2024-2909?
The root cause of CVE-2024-2909 is the manipulation of the 'bandwidth' argument in the setAction function.
Which devices are impacted by CVE-2024-2909?
CVE-2024-2909 impacts Ruijie RG-EG350 devices up to version 20240318.