Ruijie RG-NBR2600S Gateway Buffer Overflow Vulnerability Allowing Denial-of-Service and Arbitrary Command Execution

Vulnerability

A buffer overflow vulnerability has been identified in the Ruijie RG-NBR2600S Gateway, specifically in version 10.3(4b12). The vulnerability arises from inadequate length verification related to the configuration of source address NAT rules. Attackers who successfully exploit this issue can cause the device to crash or execute arbitrary commands.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing the device to crash, and allows for arbitrary command execution on the affected device.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.