CVE-2024-4816 | Ruijie RG-UAC up to 20240506 gre_add_commit.php name/remote/local/IP os command injection
A vulnerability categorized as critical has been discovered in Ruijie RG-UAC up to 20240506. This affects an unknown part of the file /view/networkConfig/GRE/gre_add_commit.php. Such manipulation of the argument name/remote/local/IP leads to os command injection.
This vulnerability is documented as CVE-2024-4816. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.