CVE-2019-16640

July 16, 2024, 6 p.m.

Product(s) Impacted

Ruijie EG-2000 series gateway

  • 11.9 B11P1

Description

An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mishandled (%00 and /var/./html are not checked), which can allow an attacker to upload any file to the gateway. This affects EG-2000SE EG_RGOS 11.9 B11P1.

Weaknesses

Date

Published: July 16, 2024, 5:15 p.m.

Last Modified: July 16, 2024, 6 p.m.

Status : Awaiting Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

cve@mitre.org

References

https://0x.mk/?p=239
cve@mitre.org