OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleset in file /usr/local/lua/devconfig/configretain.lua.
OS Command Injection vulnerability in Ruijie M18 EW3.0(1)B11P226M1810223116 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleget in file /usr/local/lua/devsta/networkConnect.lua.
A command injection vulnerability in RG-EW series home routers and repeaters v.EW3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH3.0(1)B11P219, RG-EG series business VPN routers v.EG3.0(1)B11P219, EAP and RAP series wireless access points v.AP3.0(1)B11P219, and NBC series wireless controllers v.AC3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH3.0(1)B11P218, RG-EG series business VPN routers EG3.0(1)B11P216, EAP and RAP series wireless access points AP3.0(1)B11P218, NBC series wireless controllers AC3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.
Ruijie Networks RG-EW1200 Wireless Routers EW3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.