CVE-2024-4508 | Ruijie RG-UAC up to 20240428 static_route_edit_ipv6.php oldipmask/oldgateway/olddevname os command injection
A vulnerability identified as critical has been detected in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. The manipulation of the argument oldipmask/oldgateway/olddevname leads to os command injection.
This vulnerability is documented as CVE-2024-4508. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.