ReyeeOS 1.204.1614 Man-in-the-Middle Remote Code Execution via CWMP
Vulnerability Description
ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53881
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Riyan Firmansyah of Seclab
References
More from Ruijie
View All →Affected Vendor
Ruijie
View all reports →