CVE-2024-4503: Ruijie RG-UAC dhcp_relay_commit.php os command injection
A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcprelaycommit.php. The manipulation of the argument interfacefrom leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263107. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4503?
CVE-2024-4503 is classified as a critical vulnerability.
What type of vulnerability is CVE-2024-4503?
CVE-2024-4503 is an OS command injection vulnerability.
Which software versions are affected by CVE-2024-4503?
CVE-2024-4503 affects Ruijie RG-UAC versions up to 20240428.
How can I confirm if my system is vulnerable to CVE-2024-4503?
To confirm your system's vulnerability to CVE-2024-4503, review the configurations related to the /view/dhcp/dhcpConfig/dhcp_relay_commit.php file.
How do I fix CVE-2024-4503?
To fix CVE-2024-4503, apply the latest security patches or updates provided by Ruijie for the RG-UAC firmware.