Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7m9v-98cp-4m4c

Опубликовано: 22 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 4.7

Описание

A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view/vpn/autovpn/sub_commit.php. This manipulation of the argument key causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view/vpn/autovpn/sub_commit.php. This manipulation of the argument key causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 90%
0.03982
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 4.7
nvd
12 месяцев назад

A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view/vpn/autovpn/sub_commit.php. This manipulation of the argument key causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
fstec
12 месяцев назад

Уязвимость системы управления доступом к интернету и аудита Ruijie 6000-E10, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 90%
0.03982
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-77