Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.
An attacker, without any authentication, can submit a crafted request to Ruijie proxy servers, forcing them to execute HTTP requests to any network resources chosen by the attacker. This mechanism (SSRF) allows bypassing network security and reaching internal services unavailable directly from the Internet. In particular, an attacker can access AWS instance metadata (AWS cloud metadata services), which may lead to obtaining sensitive configuration and authentication data of Ruijie's cloud infrastructure.
An attacker may gain access to internal Ruijie services and data from AWS cloud infrastructure, including potentially sensitive authentication and configuration data. This could lead to further compromise of the manufacturer's cloud environment and devices managed by this infrastructure.
Ruijie Reyee OS should be updated to version 2.320.x or newer. Detailed information regarding patches is available in the ICS-CERT advisory ICSA-24-338-01 published by CISA.
Ruijie Reyee OS in versions from 2.206.x to versions below 2.320.x (not inclusive)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRuijienetworks Reyee Os
OSRuijienetworks2.206.0 – 2.320.0 (excl.)
Related vulnerabilities
ReyeeOS: RCE przez niezaszyfrowaną komunikację CWMP (MitM)
RCE poprzez niebezpieczną funkcję w Ruijie Reyee OS — wykonanie dowolnych poleceń OS
Słaby mechanizm zmiany hasła w Ruijie Reyee OS — podatność na brute force
Ruijie Reyee OS — nieautoryzowane polecenia do urządzeń przez MQTT
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary co...