Ruijie X60 and RG-EW1200 OS Command Injection Vulnerability
Vulnerability
An OS command injection vulnerability has been identified in Ruijie X60 PRO (versions X60_10212014RG-X60 PRO V1.00/V2.00) and RG-EW1200 running ReyeeOS301. This vulnerability allows authenticated remote attackers to execute arbitrary commands on the affected device by sending specially crafted POST requests to a vulnerable Lua service.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
Reproduction
To reproduce this vulnerability, send a POST request to the 'module_get' endpoint in 'networkConnect.lua' with a payload that includes the desired command to be executed. This can be done using a tool like curl or Postman, ensuring that the request is authenticated.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
