CVE-2024-42936: Code Injection
The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42936?
CVE-2024-42936 has been classified as a high-severity vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2024-42936?
To fix CVE-2024-42936, it is recommended to update the firmware of the Ruijie RG-EW300N to the latest version provided by the vendor.
What devices are affected by CVE-2024-42936?
CVE-2024-42936 specifically affects the Ruijie RG-EW300N router running firmware ReyeeOS 1.300.1422.
What type of attack can be executed via CVE-2024-42936?
CVE-2024-42936 allows an attacker to perform Remote Code Execution by sending a modified MQTT broker message.
Is there a workaround for CVE-2024-42936 while waiting for a patch?
Currently, the best workaround for CVE-2024-42936 is to restrict access to the MQTT broker and monitor network traffic for unusual activity.