A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi.
The vulnerability (CWE-287 — Improper Authentication) consists of the ability to send a specially crafted HTTP POST request to the /user.cgi endpoint without needing valid credentials. The authentication mechanism is completely bypassed in this case, resulting in granting the attacker unlimited access to the administrative interface. The attack is possible remotely over the network, requires no user interaction, and does not require any prior privileges.
An attacker gains unlimited access to administrative functions of the device, allowing for switch configuration changes, potential full takeover of the device, and threats to the confidentiality and availability of network infrastructure.
Apply patches available from the manufacturer according to references. Until updates are implemented, it is recommended to restrict access to the device management interface only to trusted hosts or management networks (e.g., via firewall or dedicated management VLAN) and disable access to the administrative panel from public networks.
Ruijie switches from the RG-ES series with firmware version ESW_1.0(1)B1P39: Ruijie RG-ES216GC Firmware, Ruijie RG-ES206MG-P Firmware, Ruijie RG-ES224GC, Ruijie RG-ES216GC-V2, Ruijie RG-ES218GC-P
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:HRuijie Rg Es205gc
HWRuijieall versionsRuijie Rg Es205gc Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es205gc P
HWRuijieall versionsRuijie Rg Es205gc P Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es206gc P
HWRuijieall versionsRuijie Rg Es206gc P Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35Ruijie Rg Es206gs P
HWRuijieall versionsRuijie Rg Es206gs P Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es206mg P
HWRuijieall versionsRuijie Rg Es206mg P Firmware
OSRuijieesw_1.0\(1\)b1p42_release\(12142711\)Ruijie Rg Es208gc
HWRuijieall versionsRuijie Rg Es208gc Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es209gc P
HWRuijieall versionsRuijie Rg Es209gc P Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es209mg P
HWRuijieall versionsRuijie Rg Es209mg P Firmware
OSRuijieesw_1.0\(1\)b1p42_release\(12142711\)Ruijie Rg Es210gc Lp
HWRuijieall versionsRuijie Rg Es210gc Lp Firmware
OSRuijieesw_1.0\(1\)b1p27Ruijie Rg Es210gs P
HWRuijieall versionsRuijie Rg Es210gs P Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es216gc
HWRuijieall versionsRuijie Rg Es216gc Firmware
OSRuijieesw_1.0\(1\)b1p27Ruijie Rg Es216gc V2
HWRuijieall versionsRuijie Rg Es216gc V2 Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es218gc P
HWRuijieall versionsRuijie Rg Es218gc P Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35Ruijie Rg Es220gs P
HWRuijieall versionsRuijie Rg Es220gs P Firmware
OSRuijieesw_1.0\(1\)b1p27esw_1.0\(1\)b1p35esw_1.0\(1\)b1p39Ruijie Rg Es224gc
HWRuijieall versionsRuijie Rg Es224gc Firmware
OSRuijieesw_1.0\(1\)b1p27
Related vulnerabilities
RCE w usłudze mqlink.elf urządzenia Ruijie RG-EW300N via MQTT
Nieautoryzowane uzyskanie uprawnień w Ruijie RG-NBS2009G-P via config_menu.htm
Nieprawidłowe uprawnienia w Ruijie RG-NBS2009G-P umożliwiają privilege escalation
Command injection w Ruijie EG-2000SE — dostęp bez uwierzytelnienia
Ruijie RG-NBR700GW — reset hasła administratora bez weryfikacji cookie