CVE-2024-4510: Ruijie RG-UAC arp_add_commit.php os command injection
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/networkConfig/ArpTable/arpaddcommit.php. The manipulation of the argument textipaddr/textmacaddr leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263114 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch VDB-263114 - Compensating control
Mitigate the risk by preventing remote access to the Ruijie RG-UAC endpoint/path that exposes /view/networkConfig/ArpTable/arp_add_commit.php (e.g., restrict access via network firewall/ACL to only trusted management hosts).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4510?
CVE-2024-4510 has been rated as critical due to its potential impact on system security.
How do I fix CVE-2024-4510?
To remediate CVE-2024-4510, update your Ruijie RG-UAC firmware to a version later than 20240428.
What component is affected by CVE-2024-4510?
CVE-2024-4510 affects the file /view/networkConfig/ArpTable/arp_add_commit.php in Ruijie RG-UAC devices.
What kind of vulnerability is CVE-2024-4510?
CVE-2024-4510 is a command injection vulnerability caused by improper validation of input parameters.
Is my device vulnerable to CVE-2024-4510?
If you are using Ruijie RG-UAC firmware version up to and including 20240428, your device is vulnerable to CVE-2024-4510.