Executive brief
Ruijie Networks switches, which are used to manage corporate and data center network traffic, contain a security flaw in their web management interface. An unauthenticated attacker can remotely access sensitive system files, including configuration data and administrative credentials. This could allow an attacker to take full control of the network switch, leading to data interception or network-wide service disruptions.
Technical details
A directory traversal vulnerability exists in the Ruijie Networks Switch eWeb S29_RGOS version 11.4(1)B12P11. The flaw is located in the /download.do endpoint, which fails to properly sanitize the 'file' parameter. An unauthenticated remote attacker can use '../' sequences to escape the intended directory and download arbitrary files from the system. Successful exploitation allows the retrieval of 'config.text', which contains plaintext administrative credentials, network settings, and SNMP community strings. A public exploit (PoC) is available on Exploit-DB.
Affected products
- Ruijie Networks eWeb S29_RGOS 11.4(1)B12P11
Timeline
- 2020-08-19: disclosed: Initial exploit published on Exploit-DB
- 2026-01-29: advisory: CVE published/updated via VulnCheck/NVD