Ruijie NBR Series Routers Information Disclosure Vulnerability

Vulnerability

An information disclosure vulnerability has been identified in Ruijie NBR series routers, specifically in the NBR2000G, NBR1300G, and NBR1000 models. The vulnerability arises in the /WEB_VMS/LEVEL15/ endpoint, where an unauthenticated attacker can retrieve administrative account credentials in plaintext. This is achieved by sending a crafted POST request with modified Cookie headers and specially formatted parameters. The issue stems from inadequate authentication checks and flawed backend logic, allowing direct access to sensitive user data.

Impact

Exploitation of this vulnerability leads to unauthorized access to administrative credentials, allowing attackers to gain elevated privileges on the affected router.

Reproduction

To reproduce this vulnerability, modify the Cookie headers to include 'auth' and 'user' values. Then, send a POST request to the '/WEB_VMS/LEVEL15/' endpoint with the 'command' parameter set to 'show webmaster users', the 'strurl' parameter set to 'exec' with a specific control character, the 'mode' parameter set to 'PRIV_EXEC', and the 'signname' parameter set to 'Red-Giant'. This will result in the disclosure of the admin account's username and password.

Added: Jul 2, 2025, 2:25 PM
Updated: Jul 2, 2025, 2:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.