Ruijie RG-EG Remote Code Execution Scanner
Targets the /cgi-bin/upload.cgi endpoint with crafted POST requests to achieve unauthenticated remote code execution.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
1 month 2 days
Scan only one
URL
Toolbox
The Ruijie RG-EG easy gateway is a web management system used by network administrators to configure and manage network devices like routers, switches, and access points. Its interface simplifies network monitoring and adjustments, making it popular in small to large enterprises. The system's comprehensive features ensure reliable connectivity and performance, with administrators valuing its user-friendly design for efficient configuration and troubleshooting. As a crucial component in IT infrastructures, the RG-EG helps maintain optimal network operation and security.
Remote Code Execution (RCE) is a critical vulnerability that allows attackers to execute arbitrary commands on the targeted device. This flaw arises when the application fails to properly sanitize user input before processing it in system-level functions. In the Ruijie RG-EG, insufficient validation of HTTP request parameters enables attackers to inject malicious payloads that are executed by the underlying operating system, leading to full device compromise.
The vulnerability specifically affects the /cgi-bin/upload.cgi endpoint, which handles file uploads and configuration updates. By sending a specially crafted POST request with a manipulated 'filename' parameter containing command injection sequences, an attacker can bypass authentication and execute arbitrary system commands. This endpoint lacks proper input filtering, allowing shell metacharacters to be interpreted by the server's command interpreter.
Successful exploitation grants an attacker complete control over the Ruijie RG-EG device, enabling them to modify network configurations, intercept traffic, deploy malware, or pivot to internal network resources. Given the device's role as a network gateway, this can lead to widespread disruption, data exfiltration, and persistent unauthorized access. The high CVSS score of 9.0 reflects the severe impact and ease of exploitation.