Ruijie ReyeeOS
cpe:2.3:o:ruijienetworks:reyee_os:*:*:*:*:*:*:*
- 1.204.1614
This vulnerability is being actively exploited in the wild.
A vulnerability in ReyeeOS version 1.204.1614 allows for unencrypted CWMP communication, enabling man-in-the-middle attacks. Exploiting this flaw, attackers can intercept and manipulate device communications by creating a fake CWMP server that injects and executes arbitrary commands on affected Ruijie Reyee Cloud devices. The vulnerability arises from unprotected HTTP polling requests from the devices to the CWMP server.
Exploitation of this vulnerability allows for remote code execution on the affected device.
To reproduce this vulnerability, set up a fake CWMP server that intercepts unencrypted HTTP requests. When a Ruijie Reyee Cloud device sends a polling request to the CWMP server, the fake server can respond with injected commands that the device will execute.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.