CVE-2023-48849

Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.
References
Link Resource
https://github.com/delsploit/CVE-2023-48849 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ruijie:rg-eg1000c_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg1000c:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ruijie:rg-eg1000e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg1000e:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ruijie:rg-eg105g_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ruijie:rg-eg105g_v2_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g_v2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ruijie:rg-eg105g-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g-e:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ruijie:rg-eg105g-p_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g-p:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ruijie:rg-eg105g-pe_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g-pe:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ruijie:rg-eg105gw\(t\)_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105gw\(t\):-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ruijie:rg-eg105gw-x_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105gw-x:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ruijie:rg-eg2000ce_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg2000ce:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ruijie:rg-eg209gs_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg209gs:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ruijie:rg-eg2100-p_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg2100-p:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:ruijie:rg-eg210g-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg210g-e:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:ruijie:rg-eg210g-p_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg210g-p:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:ruijie:rg-eg210g-pe_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg210g-pe:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:ruijie:rg-eg3000eu_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3000eu:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:ruijie:rg-eg3000xe_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3000xe:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:ruijie:rg-eg305gh-p-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg305gh-p-e:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:ruijie:rg-eg310gh-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg310gh-e:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:ruijie:rg-eg3230_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3230:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:ruijie:rg-eg3250_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3250:-:*:*:*:*:*:*:*

History

11 Dec 2023, 16:18

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:o:ruijie:rg-eg3000xe_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg3000eu_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g-p:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg1000c_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg105g-p_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg209gs_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg2100-p:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg2000ce:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg105gw-x_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3000eu:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg210g-pe:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg2000ce_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g_v2:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg105gw\(t\)_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3250:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg105g_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg1000e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg3250_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg210g-p_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3230:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g-e:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg105g-pe_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg209gs:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg310gh-e:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg1000c:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg210g-p:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg210g-e:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg210g-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg305gh-p-e:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg310gh-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg3000xe:-:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg1000e:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg3230_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg2100-p_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg105g-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg210g-pe_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105g-pe:-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg105g_v2_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105gw\(t\):-:*:*:*:*:*:*:*
cpe:2.3:o:ruijie:rg-eg305gh-p-e_firmware:3.0\(1\)b11p216:*:*:*:*:*:*:*
cpe:2.3:h:ruijie:rg-eg105gw-x:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/delsploit/CVE-2023-48849 - () https://github.com/delsploit/CVE-2023-48849 - Exploit, Third Party Advisory
First Time Ruijie rg-eg1000e
Ruijie rg-eg209gs Firmware
Ruijie rg-eg210g-e
Ruijie rg-eg2100-p Firmware
Ruijie rg-eg105g-p Firmware
Ruijie rg-eg105gw\(t\)
Ruijie rg-eg3000xe Firmware
Ruijie rg-eg105g-p
Ruijie rg-eg210g-e Firmware
Ruijie rg-eg105g-e Firmware
Ruijie rg-eg105gw-x
Ruijie rg-eg310gh-e Firmware
Ruijie rg-eg209gs
Ruijie rg-eg105g V2
Ruijie rg-eg105g-pe Firmware
Ruijie rg-eg3230 Firmware
Ruijie rg-eg105g-e
Ruijie rg-eg3000eu Firmware
Ruijie rg-eg2000ce
Ruijie rg-eg210g-p Firmware
Ruijie rg-eg2000ce Firmware
Ruijie rg-eg105g V2 Firmware
Ruijie rg-eg210g-p
Ruijie
Ruijie rg-eg105g-pe
Ruijie rg-eg305gh-p-e Firmware
Ruijie rg-eg305gh-p-e
Ruijie rg-eg210g-pe
Ruijie rg-eg105gw-x Firmware
Ruijie rg-eg1000c
Ruijie rg-eg3000xe
Ruijie rg-eg105gw\(t\) Firmware
Ruijie rg-eg3000eu
Ruijie rg-eg105g
Ruijie rg-eg3230
Ruijie rg-eg105g Firmware
Ruijie rg-eg1000e Firmware
Ruijie rg-eg210g-pe Firmware
Ruijie rg-eg1000c Firmware
Ruijie rg-eg3250
Ruijie rg-eg310gh-e
Ruijie rg-eg2100-p
Ruijie rg-eg3250 Firmware

06 Dec 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-06 08:15

Updated : 2023-12-11 16:18


NVD link : CVE-2023-48849

Mitre link : CVE-2023-48849

CVE.ORG link : CVE-2023-48849


JSON object : View

Products Affected

ruijie

  • rg-eg210g-p
  • rg-eg310gh-e
  • rg-eg105gw-x
  • rg-eg105gw\(t\)_firmware
  • rg-eg210g-pe_firmware
  • rg-eg3250
  • rg-eg105g_v2
  • rg-eg2100-p_firmware
  • rg-eg1000c_firmware
  • rg-eg3000xe_firmware
  • rg-eg3000eu
  • rg-eg1000e_firmware
  • rg-eg310gh-e_firmware
  • rg-eg210g-e
  • rg-eg3000xe
  • rg-eg105g_firmware
  • rg-eg209gs
  • rg-eg305gh-p-e
  • rg-eg3250_firmware
  • rg-eg210g-p_firmware
  • rg-eg3000eu_firmware
  • rg-eg210g-e_firmware
  • rg-eg105g
  • rg-eg105g-e_firmware
  • rg-eg209gs_firmware
  • rg-eg2100-p
  • rg-eg210g-pe
  • rg-eg105g_v2_firmware
  • rg-eg105g-p
  • rg-eg105gw\(t\)
  • rg-eg105g-p_firmware
  • rg-eg3230
  • rg-eg1000c
  • rg-eg305gh-p-e_firmware
  • rg-eg3230_firmware
  • rg-eg105g-e
  • rg-eg2000ce
  • rg-eg105g-pe_firmware
  • rg-eg1000e
  • rg-eg2000ce_firmware
  • rg-eg105g-pe
  • rg-eg105gw-x_firmware