Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. The manipulation of the argument interface_from leads to os command injection. The attack can be launched remotely. The… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation of the argument ifName leads to os command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file /view/bugSolve/captureData/commit.php. The manipulation of the argument tcpDump leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 5.0% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 27/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the file /view/network Config/GRE/gre_edit_commit.php. The manipulation of the argument name leads to os command injection. The attack may be initiated remotely. The exploit… | |
| Aplazada | Alta (8.8) | 0.83% | — | Ruijie Rg-rsr10-01g-tAIRuijie Rg-rsr10-01g-twAI | 23/4/2024 | 17/6/2026 | An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910) allows attackers to execute arbitrary code via the common_quick_config.lua file. | |
| Aplazada | Alta (8.8) | 13% | — | Ruijie Rg-rsr10-01g-tAI | 22/4/2024 | 17/6/2026 | An issue in ruijie.com/cn RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 and RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 allows a remote attacker to execute arbitrary code via a crafted HTTP request. | |
| Analizada | Crítica (9.8) | 0.72% | — | Ruijie Rg-nbr700gw Firmware | 30/3/2024 | 17/6/2026 | Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise. | |
| Analizada | Alta (8.8) | 3.7% | — | Ruijie Rg-eg350 Firmware | 26/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this issue is the function vpnAction of the file /itbox_pi/vpn_quickset_service.php?a=set_vpn of the component HTTP POST Request Handler. The manipulation of the argument ip/port/user/pass/dns/startIp leads… | |
| Analizada | Alta (8.8) | 4.0% | — | Ruijie Rg-eg350 Firmware | 26/3/2024 | 17/6/2026 | A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the file /itbox_pi/networksafe.php?a=set of the component HTTP POST Request Handler. The manipulation of the argument bandwidth leads to os command injection. The attack can… | |
| Analizada | Alta (7.3) | 2.8% | — | Ruijie Rg-nbs2009g-p Firmware | 19/3/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /EXCU_SHELL. The manipulation of the argument Command1 leads to command injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.79% | — | Ruijie Rg-nbs2009g-p Firmware | 19/3/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unknown function of the file /system/passwdManage.htm of the component Password Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.2% | — | Ruijie Rg-ws6008 FirmwareRuijie Rg-ws6108 Firmware | 20/12/2023 | 17/6/2026 | Ruijie WS6008 v1.x v2.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 and WS6108 v1.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 was discovered to contain a command injection vulnerability via the function downFiles. | |
| Modificada | Crítica (9.8) | 1.3% | 💥 PoC | Ruijie Rg-eg1000c FirmwareRuijie Rg-eg1000e FirmwareRuijie Rg-eg105g FirmwareRuijie Rg-eg105g V2 Firmware+17 | 6/12/2023 | 17/6/2026 | Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering. | |
| Modificada | Alta (8.8) | 58% | 💥 Exploit | Ruijienetworks Rg-ew1200g Firmware | 18/8/2023 | 17/6/2026 | A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 2.6% | — | Ruijie Rg-ew1200 FirmwareRuijie Rg-ew1200g PRO FirmwareRuijie Rg-ew1200r FirmwareRuijie Rg-ew1300g Firmware+92 | 17/8/2023 | 17/6/2026 | A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers… | |
| Modificada | Alta (8.8) | 49% | 💥 Exploit | Ruijie Rg-ew1200g Firmware | 5/8/2023 | 17/6/2026 | A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/sys/set_passwd of the component Administrator Password Handler. The manipulation leads to improper access controls. The attack can be launched… | |
| Modificada | Crítica (9.8) | 1.8% | — | Ruijie Rg-ew1200r FirmwareRuijie Rg-ew300 FirmwareRuijie Rg-ew3200gx FirmwareRuijie Rg-ew1200g Firmware+61 | 31/7/2023 | 17/6/2026 | Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless… | |
| Modificada | Alta (8.8) | 12% | — | Ruijienetworks Bcr810w Firmware | 10/7/2023 | 17/6/2026 | A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Alta (7.2) | 51% | 💥 PoC | Ruijie Rg-bcr860 Firmware | 28/6/2023 | 17/6/2026 | A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 23% | — | Ruijie Rg-ew1200g Firmware | 18/6/2023 | 17/6/2026 | A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the file app.09df2a9e44ab48766f5f.js of the component Admin Password Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The… | |
| Modificada | Alta (8.8) | 2.3% | — | Ruijienetworks Rg-ew1800gx PRO FirmwareRuijienetworks Rg-ew3200gx PRO FirmwareRuijienetworks Rg-ew1200g PRO Firmware | 26/3/2023 | 17/6/2026 | RG-EW1200G PRO Wireless Routers EW_3.0(1)B11P204, RG-EW1800GX PRO Wireless Routers EW_3.0(1)B11P204, and RG-EW3200GX PRO Wireless Routers EW_3.0(1)B11P204 were discovered to contain multiple command injection vulnerabilities via the data.ip, data.protocal, data.iface and data.package parameters in the runPackDiagnose… | |
| Modificada | Crítica (9.8) | 1.0% | — | Ruijienetworks Rg-ew1200r FirmwareRuijienetworks Rg-ew1200 FirmwareRuijienetworks Rg-ew1200g PRO Firmware | 26/3/2023 | 17/6/2026 | Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function. | |
| Modificada | Crítica (9.1) | 0.89% | — | Ruijienetworks Rg-eg350 Firmware | 25/6/2022 | 17/6/2026 | RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_alarmAction at /alarm_pi/alarmService.php. | |
| Modificada | Alta (8.8) | 35% | 💥 Exploit | Ruijienetworks Reyeeos | 4/5/2022 | 9/7/2026 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless. | |
| Modificada | Crítica (9.8) | 2.1% | — | Ruijienetworks Reyeeos | 4/5/2022 | 9/7/2026 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth. |