Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

133 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)3.2%—Ruijie Rg-ew3000gxAI16/9/202616/9/2026
A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely.…
AplazadaAlta (8.5)3.2%—Ruijie Rg-ew3000gxAI16/9/202616/9/2026
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has…
AplazadaMedia (5.5)0.47%—Ruijie Rg-uacAI5/7/20266/7/2026
A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Performing a manipulation of the argument upload_image results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and…
AplazadaAlta (7.3)2.4%—Ruijie Eg105g-pAI15/6/202624/7/2026
A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of the component JSON-RPC Diagnose Endpoint. Performing a manipulation of the argument params.target results in command injection. It is possible to initiate the attack…
AplazadaAlta (7.1)0.71%—Ruijienetworks Switch Eweb S29 RgosAI29/1/202617/6/2026
The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration…
AplazadaAlta (8.6)1.4%—Ruijienetworks RG Ap180AI18/12/202530/9/2026
RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.
AnalizadaCrítica (9.2)0.31%—Ruijienetworks Reyee OS15/12/202517/6/2026
ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the…
AnalizadaAlta (8.8)2.1%—Ruijie Rg-nbs5100-24gt4sfp FirmwareRuijie Rg-s1930 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST request to the module_update in file /usr/local/lua/dev_config/ace_sw.lua.
AnalizadaAlta (8.8)2.6%—Ruijie Rg-bcr860 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis.lua.
AnalizadaAlta (8.8)3.1%—Ruijie Rg-bcr600w Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_wanobj in file /usr/lib/lua/luci/controller/admin/common.lua.
AnalizadaAlta (7.8)1.3%—Ruijie Rg-x60 PRO FirmwareRuijie Rg-ew1200 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.
AnalizadaAlta (8.8)2.6%—Ruijie Rg-ew1200g PRO FirmwareRuijie Rg-ew1300g Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.
AnalizadaAlta (8.8)2.6%—Ruijie Rg-ew1800gx FirmwareRuijie Rg-ew300n FirmwareRuijie Rg-ew1800gx PRO Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.
AnalizadaAlta (8.8)2.6%—Ruijie Rg-x60 PRO FirmwareRuijie Rg-ew1200 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.
AnalizadaAlta (8.8)2.6%—Ruijie Rg-ew3200gx FirmwareRuijie Rg-x60 PRO Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.
AnalizadaAlta (8.8)3.1%—Ruijie X30 PRO FirmwareRuijie Rg-est310 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.
AnalizadaAlta (8.8)2.6%—Ruijie Rg-ew1300g FirmwareRuijie M18-ew Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.
AnalizadaAlta (8.8)1.7%—Ruijie Rg-yst250f FirmwareRuijie Rg-est310 V2 FirmwareRuijie Reyee OSRuijie Rg-eap602 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.
AnalizadaAlta (8.8)3.1%—Ruijie Rg-bcr860 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the network_set_wan_conf in file /usr/lib/lua/luci/controller/admin/netport.lua.
AnalizadaAlta (8.8)3.1%—Ruijie Rg-bcr860 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_deal_update in file /usr/lib/lua/luci/controller/api/rcmsAPI.lua.
AnalizadaAlta (8.8)3.1%—Ruijie Rg-bcr860 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_wireless in file /usr/lib/lua/luci/control/admin/wireless.lua.
AnalizadaAlta (8.8)2.7%—Ruijie X30 PRO FirmwareRuijie Rg-eap602 FirmwareRuijie Rg-est350 FirmwareRuijie Rg-ew300 PRO Firmware+111/12/202517/6/2026
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.
AnalizadaAlta (8.8)2.3%—Ruijie Rg-bcr600w Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua.
AnalizadaAlta (8.8)2.8%—Ruijie Rg-ew1800gx FirmwareRuijie Rg-est350 Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.
AnalizadaAlta (8.8)2.6%—Ruijie Rg-ew1800gx FirmwareRuijie Rg-ew300r Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.