Ruijie RG-EW300N
cpe:2.3:h:ruijie:rg-ew300:*:*:*:*:*:*:*
- 1.300.1422
A remote code execution vulnerability has been identified in the Ruijie RG-EW300N router running ReyeeOS firmware version 1.300.1422. The issue arises in the mqlink.elf service component, where intercepted and modified MQTT broker messages can be used to execute shell commands on the device.
Exploitation of this vulnerability allows for arbitrary remote code execution on the affected device.
To reproduce this vulnerability, intercept MQTT messages sent to the device and modify them to include payloads that execute shell commands. The altered messages can then be sent to the device, triggering the execution of the embedded commands.
Users can upgrade to Ruijie RG-EW300N firmware version 1.313.2406 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.