Ruijie EG Series Routers version EG3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.
Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH3.0(1)B11P218, RG-EG series business VPN routers EG3.0(1)B11P216, EAP and RAP series wireless access points AP3.0(1)B11P218, NBC series wireless controllers AC3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.