PT-2026-55784 · Ruijie · Rg-Uac
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ruijie RG-UAC versions prior to 1.0-R1.8.2.p5
Description
A remote unrestricted upload issue exists within an unknown function of the
user auth commit.php file. By manipulating the upload image argument, an attacker can upload files without restriction.Recommendations
Update Ruijie RG-UAC to a version later than 1.0-R1.8.2.p5.
As a temporary mitigation, restrict access to the
user auth commit.php file or avoid using the upload image argument.Exploit
Fix
Unrestricted File Upload
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rg-Uac