Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.
Reyee OS improperly manages MQTT client permissions — a client authenticated with credentials of a single device can publish messages to MQTT topics that should be accessible only to the trusted cloud backend. An attacker who has obtained credentials of any device can connect to the MQTT broker and send crafted commands to other devices managed by the Ruijie cloud. The vulnerability is classified as CWE-280 (Improper Handling of Insufficient Permissions or Privileges), indicating a lack of proper verification of permission scope at the MQTT communication level.
An attacker possessing authentication credentials of one device can execute unauthorized commands on other network devices in the Reyee ecosystem, effectively impersonating the manufacturer's cloud server — which may lead to takeover of network devices, changes to their configuration, or disruption of infrastructure operation.
Update Ruijie Reyee OS to version 2.320.x or later. Detailed information regarding updates is available in the ICS-CERT notification at: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01. Additionally, it is recommended to restrict access to the MQTT broker at the network level and monitor unauthorized MQTT connections.
Ruijie Reyee OS in versions from 2.206.x to versions prior to 2.320.x.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRuijienetworks Reyee Os
OSRuijienetworks2.206.0 – 2.320.0 (excl.)
Related vulnerabilities
ReyeeOS: RCE przez niezaszyfrowaną komunikację CWMP (MitM)
RCE poprzez niebezpieczną funkcję w Ruijie Reyee OS — wykonanie dowolnych poleceń OS
SSRF w Ruijie Reyee OS — dostęp do wewnętrznej infrastruktury chmurowej
Słaby mechanizm zmiany hasła w Ruijie Reyee OS — podatność na brute force
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary co...