Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr29-wjp4-gr5r

Опубликовано: 02 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve administrative account credentials in plaintext. This flaw allows direct disclosure of sensitive user data due to improper authentication checks and insecure backend logic.

An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve administrative account credentials in plaintext. This flaw allows direct disclosure of sensitive user data due to improper authentication checks and insecure backend logic.

EPSS

Процентиль: 65%
0.00492
Низкий

8.7 High

CVSS4

Дефекты

CWE-200
CWE-306

Связанные уязвимости

nvd
7 месяцев назад

An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve administrative account credentials in plaintext. This flaw allows direct disclosure of sensitive user data due to improper authentication checks and insecure backend logic. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость микропрограммного обеспечения маршрутизаторов Ruijie NBR2000G, NBR1300G и Ruijie NBR1000, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить доступ к учетной записи администратора

EPSS

Процентиль: 65%
0.00492
Низкий

8.7 High

CVSS4

Дефекты

CWE-200
CWE-306