Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 3.6% | — | Ruijie Rg-uacAI | 15/10/2025 | 17/6/2026 | Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute arbitrary commands on the host. Successful… | |
| Aplazada | Baja (2) | 3.8% | — | Ruijie Nbr2100g-eAI | 29/9/2025 | 17/6/2026 | A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue is the function listAction of the file /itbox_pi/branch_passw.php?a=list. Performing manipulation of the argument city results in os command injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Baja (2) | 4.0% | — | Ruijie 6000-e10AI | 22/9/2025 | 17/6/2026 | A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view/vpn/autovpn/sub_commit.php. This manipulation of the argument key causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Crítica (9.4) | 0.53% | — | Ruijie Rg-es228gs-p FirmwareRuijie Rg-es209gc-p FirmwareRuijie Rg-es205gc-p FirmwareRuijie Rg-es205gc Firmware+16 | 3/9/2025 | 17/6/2026 | A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi. | |
| Analizada | Baja (2) | 15% | — | Ruijie Ws7204-a Firmware | 25/8/2025 | 17/6/2026 | A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch_import.php?a=branch_list. Such manipulation of the argument province leads to os command injection. The attack can be executed remotely. The exploit is publicly… | |
| Aplazada | Media (6.3) | 0.15% | — | Ruijie Eg306mgAIStrongswanAI | 9/8/2025 | 17/6/2026 | A vulnerability was found in Ruijie EG306MG 3.0(1)B11P309. It has been rated as problematic. This issue affects some unknown processing of the file /etc/strongswan.conf of the component strongSwan. The manipulation of the argument i_dont_care_about_security_and_use_aggressive_mode_psk leads to missing encryption of… | |
| Aplazada | Alta (8.7) | 10% | — | Ruijie Nbr2000gAIRuijie Nbr1300gAIRuijie Nbr1000AI | 2/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve… | |
| Analizada | Media (5.1) | 0.25% | — | Ruijie Rg-nbr2600s Firmware | 11/2/2025 | 17/6/2026 | Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | |
| Analizada | Crítica (9.8) | 1.1% | — | Ruijie Reyee OS | 21/1/2025 | 17/6/2026 | The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message. | |
| Analizada | Crítica (9.2) | 0.69% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands. | |
| Analizada | Crítica (9.3) | 0.60% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services. | |
| Analizada | Alta (8.7) | 0.39% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, and receive partial messages being sent to and from devices. | |
| Analizada | Alta (7.1) | 0.28% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and sniffing the RAW WIFI signal. | |
| Analizada | Crítica (9.2) | 0.40% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud. | |
| Analizada | Alta (8.7) | 0.46% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials. | |
| Analizada | Alta (7.1) | 0.53% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to invalidate a legitimate user's session and cause a denial-of-service attack on a user's account. | |
| Analizada | Crítica (9.3) | 0.67% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks. | |
| Analizada | Alta (8.7) | 0.39% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone number and part of the email address. | |
| Analizada | Alta (7.1) | 0.43% | — | Ruijienetworks Reyee OS | 6/12/2024 | 17/6/2026 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services | |
| Aplazada | Media (6.5) | 7.1% | — | Ruijie Nbr800gAI | 13/11/2024 | 17/6/2026 | Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter. | |
| Modificada | Alta (7.5) | 0.39% | — | Ruijie Nbr3000d-e Firmware | 15/10/2024 | 17/6/2026 | An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component. | |
| Modificada | Crítica (9.8) | 0.66% | — | Ruijie Rg-nbs2009g-p Firmware | 2/10/2024 | 17/6/2026 | Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component. | |
| Modificada | Crítica (9.8) | 28% | 💥 Exploit | Ruijie Rg-nbs2009g-p Firmware | 2/10/2024 | 17/6/2026 | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. | |
| Analizada | Media (5.1) | 0.68% | — | Ruijie Eg2000k Firmware | 26/8/2024 | 17/6/2026 | A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical. This vulnerability affects unknown code of the file /tool/index.php?c=download&a=save. The manipulation of the argument content leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Alta (8.4) | 0.30% | — | Ruijie Eg-2000se Firmware | 16/7/2024 | 17/6/2026 | An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login to any account, without providing its password. This affects EG-2000SE EG_RGOS 11.1(1)B1. |