Junglewise Threat Intelligence

CVE-2020-37015: Ruijie Networks Switch eWeb directory traversal in download.do

CVE-2020-37015 · Severity: high · CVSS 7.5 · Published 2026-01-29

Executive brief

Ruijie Networks switches, which are used to manage corporate and data center network traffic, contain a security flaw in their web management interface. An unauthenticated attacker can remotely access sensitive system files, including configuration data and administrative credentials. This could allow an attacker to take full control of the network switch, leading to data interception or network-wide service disruptions.

Technical details

A directory traversal vulnerability exists in the Ruijie Networks Switch eWeb S29_RGOS version 11.4(1)B12P11. The flaw is located in the /download.do endpoint, which fails to properly sanitize the 'file' parameter. An unauthenticated remote attacker can use '../' sequences to escape the intended directory and download arbitrary files from the system. Successful exploitation allows the retrieval of 'config.text', which contains plaintext administrative credentials, network settings, and SNMP community strings. A public exploit (PoC) is available on Exploit-DB.

Affected products

  • Ruijie Networks eWeb S29_RGOS 11.4(1)B12P11

Timeline

  • 2020-08-19: disclosed: Initial exploit published on Exploit-DB
  • 2026-01-29: advisory: CVE published/updated via VulnCheck/NVD

References