CVE-2024-6186: Ruijie RG-UAC commit.php os command injection
A vulnerability, which was classified as critical, was found in Ruijie RG-UAC 1.0. This affects an unknown part of the file /view/userAuthentication/SSO/commit.php. The manipulation of the argument adlogname leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269157 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6186?
CVE-2024-6186 is classified as a critical vulnerability.
What type of attack can CVE-2024-6186 facilitate?
CVE-2024-6186 can facilitate OS command injection attacks due to improper handling of the ad_log_name argument.
Which software is impacted by CVE-2024-6186?
CVE-2024-6186 affects Ruijie RG-UAC version 1.0.
How can I mitigate the risks associated with CVE-2024-6186?
To mitigate CVE-2024-6186, ensure that you implement input validation and sanitization for the ad_log_name parameter.
Is there an available patch for CVE-2024-6186?
As of now, there is no specific patch released for CVE-2024-6186, so upgrading to the latest firmware is advised.