CVE-2024-4507 | Ruijie RG-UAC up to 20240428 static_route_add_ipv6.php text_prefixlen/text_gateway/devname os command injection
A vulnerability categorized as critical has been discovered in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. Executing manipulation of the argument text_prefixlen/text_gateway/devname can lead to os command injection.
This vulnerability is registered as CVE-2024-4507. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.