CRITICAL🇵🇱 Wersja polska

CVE-2023-53881

CVSS 9.2v4.0pub. 2025-12-15upd. 2025-12-18

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.

🤖 AI Analysis
How it works

Devices running ReyeeOS send unencrypted HTTP polling requests to the CWMP server (TR-069 protocol). An attacker positioned on the network path can intercept this communication and substitute a fake CWMP server. Since the requests are not protected by encryption or integrity verification, the attacker can inject arbitrary commands into the response, which the device will then execute with the appropriate privileges.

Impact

An attacker can remotely execute arbitrary commands (RCE) on Ruijie Reyee Cloud devices, gaining full control over the device, including the ability to modify configuration, intercept network traffic, or use the device as an entry point to the internal network.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Additionally, until the fix is deployed, network segmentation is recommended, restricting device access to the Internet through a dedicated firewall, and monitoring network traffic for suspicious CWMP connections.

Who is affected

Ruijie Networks ReyeeOS version 1.204.1614 on Ruijie Reyee Cloud devices

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Ruijienetworks Reyee Os

    OS
    Ruijienetworks
    1.204.1614
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-52324CRITICAL9.2PL ✓same product

RCE poprzez niebezpieczną funkcję w Ruijie Reyee OS — wykonanie dowolnych poleceń OS

CVE-2024-46874CRITICAL9.2PL ✓same product

Ruijie Reyee OS — nieautoryzowane polecenia do urządzeń przez MQTT

CVE-2024-47547CRITICAL9.3PL ✓same product

Słaby mechanizm zmiany hasła w Ruijie Reyee OS — podatność na brute force

CVE-2024-48874CRITICAL9.3PL ✓same product

SSRF w Ruijie Reyee OS — dostęp do wewnętrznej infrastruktury chmurowej

CVE-2025-56077HIGH8.8same product

OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary co...