Ruijie RG-EW300N Remote Code Execution Vulnerability via Modified MQTT Broker Message

Vulnerability

A remote code execution vulnerability has been identified in the Ruijie RG-EW300N router running ReyeeOS firmware version 1.300.1422. The issue arises in the mqlink.elf service component, where intercepted and modified MQTT broker messages can be used to execute shell commands on the device.

Impact

Exploitation of this vulnerability allows for arbitrary remote code execution on the affected device.

Reproduction

To reproduce this vulnerability, intercept MQTT messages sent to the device and modify them to include payloads that execute shell commands. The altered messages can then be sent to the device, triggering the execution of the embedded commands.

Remediation

Users can upgrade to Ruijie RG-EW300N firmware version 1.313.2406 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
7.2
remediation
7.7
relevance
0.0
threat
6.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.