CVE-2024-4813 | Ruijie RG-UAC up to 20240506 interface_commit.php Name os command injection
A vulnerability was found in Ruijie RG-UAC up to 20240506. It has been classified as critical. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation of the argument Name leads to os command injection.
This vulnerability is listed as CVE-2024-4813. The attack may be initiated remotely. In addition, an exploit is available.
Applying a patch is the recommended action to fix this issue.
The vendor was contacted early about this disclosure but did not respond in any way.