CVE-2024-4507: Ruijie RG-UAC static_route_add_ipv6.php os command injection
A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/staticrouteaddipv6.php. The manipulation of the argument textprefixlen/textgateway/devname leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263111. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4507?
CVE-2024-4507 is classified as a critical vulnerability affecting Ruijie RG-UAC firmware.
How do I fix CVE-2024-4507?
To fix CVE-2024-4507, you should update Ruijie RG-UAC firmware to a version later than 20240428.
What components are affected by CVE-2024-4507?
CVE-2024-4507 affects the /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php file in Ruijie RG-UAC.
What type of attack can CVE-2024-4507 facilitate?
CVE-2024-4507 can facilitate OS command injection through manipulation of specific input arguments.
Is there a workaround for CVE-2024-4507?
As of now, there are no documented workarounds for CVE-2024-4507; updating the firmware is recommended.