Executive brief
Ruijie RG-UAC, a network access control gateway, contains a security flaw that allows unauthorized users to upload files to the system. By exploiting this vulnerability, a remote attacker could potentially place malicious software on the device, leading to unauthorized access or disruption of network security services. This could compromise the integrity of the gateway and the data it protects.
Technical details
A vulnerability classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) exists in Ruijie RG-UAC firmware versions up to 1.0-R1.8.2.p5. The flaw is located within the user_auth_commit.php file, where the 'upload_image' argument is not properly validated. A remote, unauthenticated attacker can manipulate this argument to upload arbitrary files to the server. This can lead to remote code execution if the uploaded file is a script (e.g., PHP) and is accessible via the web root. Public exploit code is reportedly available.
Affected products
- Ruijie RG-UAC up to 1.0-R1.8.2.p5
Timeline
- 2026-07-05: advisory: Vulnerability published by NVD/VulDB