CVE-2023-38902

HIGHCVSS 8.8/10EPSS 2.19%

Last modified

CVE-2023-38902 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.. EPSS estimates a 2.19% chance of exploitation in the next 30 days.

Description

A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.19%

80.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RuijieRg-Ew1200 Firmware3.0\(1\)b11p219
RuijieRg-Ew1200g Pro Firmware3.0\(1\)b11p219
RuijieRg-Ew1200r Firmware3.0\(1\)b11p219
RuijieRg-Ew1300g Firmware3.0\(1\)b11p219
RuijieRg-Ew1800gx Pro Firmware3.0\(1\)b11p219
RuijieRg-Ew3000gx Pro Firmware3.0\(1\)b11p219
RuijieRg-Ew300 Pro Firmware3.0\(1\)b11p219
RuijieRg-Ew300r Firmware3.0\(1\)b11p219
RuijieRg-Ew3200gx Pro Firmware3.0\(1\)b11p219
RuijieRg-Nb3200-24gt4xs Firmware3.0\(1\)b11p219
RuijieRg-Nbs1850gc Firmware3.0\(1\)b11p219
RuijieRg-Nbs1850gc V2 Firmware3.0\(1\)b11p219
RuijieRg-Nbs2000 Firmware3.0\(1\)b11p219
RuijieRg-Nbs2009g-P Firmware3.0\(1\)b11p219
RuijieRg-Nbs200 Firmware3.0\(1\)b11p219
RuijieRg-Nbs2026g-P Firmware3.0\(1\)b11p219
RuijieRg-Nbs2026g Firmware3.0\(1\)b11p219
RuijieRg-Nbs226f Firmware3.0\(1\)b11p219
RuijieRg-Nbs228f Firmware3.0\(1\)b11p219
RuijieRg-Nbs252f Firmware3.0\(1\)b11p219
RuijieRg-Nbs3100-24gt4sfp-P Firmware3.0\(1\)b11p219
RuijieRg-Nbs3100-24gt4sfp-P V2 Firmware3.0\(1\)b11p219
RuijieRg-Nbs3100-24gt4sfp Firmware3.0\(1\)b11p219
RuijieRg-Nbs3100-48gt4sfp Firmware3.0\(1\)b11p219
RuijieRg-Nbs3100-8gt2sfp-P Firmware3.0\(1\)b11p219
RuijieRg-Nbs3100-8gt2sfp Firmware3.0\(1\)b11p219
RuijieRg-Nbs3200-24gt4xs-P Firmware3.0\(1\)b11p219
RuijieRg-Nbs3200-24sfp\/8gt4xs Firmware3.0\(1\)b11p219
RuijieRg-Nbs3200-48gt4xs-P Firmware3.0\(1\)b11p219
RuijieRg-Nbs3200-48gt4xs Firmware3.0\(1\)b11p219
RuijieRg-Nbs5100-24gt4sfp Firmware3.0\(1\)b11p219
RuijieRg-Nbs5100-48gt4sfp Firmware3.0\(1\)b11p219
RuijieRg-Nbs5200-24gt4x Firmware3.0\(1\)b11p219
RuijieRg-Nbs5200-24sfp\/8gt4xs Firmware3.0\(1\)b11p219
RuijieRg-Nbs5200-48gt4xs Firmware3.0\(1\)b11p219
RuijieRg-Nbs5300-48mg6xs Firmware3.0\(1\)b11p219
RuijieRg-Nbs5528xg Firmware3.0\(1\)b11p219
RuijieRg-Nbs5552xg Firmware3.0\(1\)b11p219
RuijieRg-Nbs5552xg V2.0 Firmware3.0\(1\)b11p219
RuijieRg-Nbs5628xg Firmware3.0\(1\)b11p219
RuijieRg-Nbs5652xg Firmware3.0\(1\)b11p219
RuijieRg-Nbs5710-24gt4sfp-E-P Firmware3.0\(1\)b11p219
RuijieRg-Nbs5710-24gt4sfp-E Firmware3.0\(1\)b11p219
RuijieRg-Nbs5710-48gt4sfp-E Firmware3.0\(1\)b11p219
RuijieRg-Nbs5750-28gt4xs-E Firmware3.0\(1\)b11p219
RuijieRg-Nbs5750v2-24gt4xs-E Firmware3.0\(1\)b11p219
RuijieRg-Nbs5750v2-24sfp4xs-E Firmware3.0\(1\)b11p219
RuijieRg-Nbs5750v2-48gt4xs-E Firmware3.0\(1\)b11p219
RuijieRg-Nbs5816xs Firmware3.0\(1\)b11p219
RuijieRg-Nbs6002 Firmware3.0\(1\)b11p219

Showing 50 of 96 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-38902?
A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
How severe is CVE-2023-38902?
CVE-2023-38902 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 2.19% probability of exploitation in the next 30 days.
How do I fix CVE-2023-38902?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-38902?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST