CRITICAL🇵🇱 Wersja polska

CVE-2024-52324

CVSS 9.2v4.0pub. 2024-12-06upd. 2024-12-10

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.

🤖 AI Analysis
How it works

Ruijie Reyee OS uses a function considered inherently unsafe (CWE-242), meaning its use introduces security risk regardless of implementation. An attacker can send a specially crafted message via the MQTT protocol, and when processed by the vulnerable device, it results in arbitrary operating system command execution. The attack can be conducted remotely over the network without requiring access credentials.

Impact

An attacker can gain full control over the device by executing arbitrary operating system commands, which may lead to device takeover, configuration modification, network disruption, or use of the device as a pivot point for further attacks.

Mitigation & patch

Ruijie Reyee OS should be updated to version 2.320.x or later. It is also recommended to restrict access to the MQTT broker exclusively to trusted hosts and to monitor MQTT traffic for anomalies. Detailed information is available in the ICS-CERT recommendation: ICSA-24-338-01.

Who is affected

Ruijie Reyee OS versions from 2.206.x to (but not including) 2.320.x

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Ruijienetworks Reyee Os

    OS
    Ruijienetworks
    2.206.0 – 2.320.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-53881CRITICAL9.2PL ✓same product

ReyeeOS: RCE przez niezaszyfrowaną komunikację CWMP (MitM)

CVE-2024-48874CRITICAL9.3PL ✓same product

SSRF w Ruijie Reyee OS — dostęp do wewnętrznej infrastruktury chmurowej

CVE-2024-47547CRITICAL9.3PL ✓same product

Słaby mechanizm zmiany hasła w Ruijie Reyee OS — podatność na brute force

CVE-2024-46874CRITICAL9.2PL ✓same product

Ruijie Reyee OS — nieautoryzowane polecenia do urządzeń przez MQTT

CVE-2025-56077HIGH8.8same product

OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary co...