CVE-2019-16639

July 16, 2024, 6 p.m.

Product(s) Impacted

Ruijie EG-2000 series gateway

  • EG_RGOS 11.9 B11P1

Description

An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who only has web interface access) to use TELNET commands and/or show admin passwords via the mode_url=exec&command= substring. This affects EG-2000SE EG_RGOS 11.9 B11P1.

Weaknesses

Date

Published: July 16, 2024, 5:15 p.m.

Last Modified: July 16, 2024, 6 p.m.

Status : Awaiting Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

cve@mitre.org

References

https://0x.mk/?p=239
cve@mitre.org