An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/configmenu.htm.
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.
A command injection vulnerability in RG-EW series home routers and repeaters v.EW3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH3.0(1)B11P219, RG-EG series business VPN routers v.EG3.0(1)B11P219, EAP and RAP series wireless access points v.AP3.0(1)B11P219, and NBC series wireless controllers v.AC3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.