HTTP POST Request Vulnerability in Ruijie RG-EG350 Gateway
CVE-2024-2910
6.3MEDIUM
What is CVE-2024-2910?
A significant security vulnerability has been identified in the Ruijie RG-EG350 Easy Gateway Management System, affecting versions up to 20240318. This vulnerability resides in the vpnAction function of the HTTP POST Request Handler within the file /itbox_pi/vpn_quickset_service.php?a=set_vpn. It allows attackers to manipulate arguments such as ip, port, user, pass, and dns/startIp, facilitating remote command injection. Given its nature, the exploit can be launched over the internet, posing a severe risk to affected systems. This issue was disclosed publicly, emphasizing the urgency for mitigation and remediation measures. More information can be found in detailed vulnerability databases and advisory resources.
Affected Version(s)
RG-EG350 20240318