CVE-2025-56752
9.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Exploitability: 3.9 / Impact: 5.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi.
Affected (43)
Products: Ruijie: Rg Es228gs P Firmware, Rg Es209gc P Firmware, Rg Es205gc P Firmware, Rg Es205gc Firmware, Rg Es208gc Firmware, Rg Es206gs P Firmware, Rg Es210gs P Firmware, Rg Es218gc P Firmware, Rg Es226gc P Firmware, Rg Es206gc P Firmware, Rg Es216gc Firmware, Rg Es224gc Firmware, Rg Es210gc Lp Firmware, Rg Es206mg P Firmware, Rg Es209mg P Firmware, Rg Nis2100 8gt2sfp Hp Firmware, Rg Nis2100 4gt2sfp Hp Firmware, Rg Es216gc V2 Firmware, Rg Es224gc V2 Firmware, Rg Es220gs P Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es228gs P | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es209gc P | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es205gc P | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es205gc | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es208gc | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es206gs P | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es210gs P | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es218gc P | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es226gc P | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es206gc P | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es216gc | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es224gc | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es210gc Lp | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p42_release(12142711) |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es206mg P | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p42_release(12142711) |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es209mg P | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p39 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Nis2100 8gt2sfp Hp | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p39 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Nis2100 4gt2sfp Hp | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es216gc V2 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es224gc V2 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version esw_1.0(1)b1p27 |
| Running on/with | Platform Versions |
|---|---|
Ruijie Rg Es220gs P | All versions |
References (1)
Source: cve@mitre.org
Third Party Advisory
Timeline
No history available yet.