Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

ReyeeOS Unencrypted CWMP Communication Vulnerability Allowing Man-in-the-Middle Remote Code Execution

Vulnerability

A vulnerability in ReyeeOS version 1.204.1614 allows for unencrypted CWMP communication, enabling man-in-the-middle attacks. Exploiting this flaw, attackers can intercept and manipulate device communications by creating a fake CWMP server that injects and executes arbitrary commands on affected Ruijie Reyee Cloud devices. The vulnerability arises from unprotected HTTP polling requests from the devices to the CWMP server.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected device.

Reproduction

To reproduce this vulnerability, set up a fake CWMP server that intercepts unencrypted HTTP requests. When a Ruijie Reyee Cloud device sends a polling request to the CWMP server, the fake server can respond with injected commands that the device will execute.

Added: Dec 15, 2025, 9:17 PM
Updated: Dec 15, 2025, 9:17 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
7.5
remediation
0.0
relevance
1.4
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.