ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.
Devices running ReyeeOS send unencrypted HTTP polling requests to the CWMP server (TR-069 protocol). An attacker positioned on the network path can intercept this communication and substitute a fake CWMP server. Since the requests are not protected by encryption or integrity verification, the attacker can inject arbitrary commands into the response, which the device will then execute with the appropriate privileges.
An attacker can remotely execute arbitrary commands (RCE) on Ruijie Reyee Cloud devices, gaining full control over the device, including the ability to modify configuration, intercept network traffic, or use the device as an entry point to the internal network.
Patches available from the manufacturer should be applied according to the references. Additionally, until the fix is deployed, network segmentation is recommended, restricting device access to the Internet through a dedicated firewall, and monitoring network traffic for suspicious CWMP connections.
Ruijie Networks ReyeeOS version 1.204.1614 on Ruijie Reyee Cloud devices
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRuijienetworks Reyee Os
OSRuijienetworks1.204.1614
Related vulnerabilities
RCE poprzez niebezpieczną funkcję w Ruijie Reyee OS — wykonanie dowolnych poleceń OS
Ruijie Reyee OS — nieautoryzowane polecenia do urządzeń przez MQTT
Słaby mechanizm zmiany hasła w Ruijie Reyee OS — podatność na brute force
SSRF w Ruijie Reyee OS — dostęp do wewnętrznej infrastruktury chmurowej
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary co...