在锐捷 RG-EW3000GX 设备的 EW_3.0(1)B11P380 固件版本中发现了一个安全漏洞。该漏洞位于组件 configChange 的文件 unifyframe-sgi.elf 中的 cc_set 函数。通过恶意操纵参数 data.url,攻击者可实施操作系统命令注入。该攻击可远程发起。此漏洞的利用方法已被公开披露,存在被实际利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ruijie | RG-EW3000GX | EW_3.0(1)B11P380 |
cpe:2.3:a:ruijie:rg-ew3000gx:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet