CVE-2024-24116
PoCUnauthenticated Privilege Gain in Ruijie RG-NBS2009G-P Switch Web UI
CVE-2024-24116 is an improper privilege-handling flaw (CWE-280) in the embedded web management interface of the Ruijie RG-NBS2009G-P switch running RGOS 10.4(1)P2 Release 9736, where the system/config_menu.htm page is not properly protected. A remote, unauthenticated attacker who can reach the switch's management HTTP service can simply request this page to gain privileged access to the device's configuration functionality, with no credentials or user interaction required (reflected in the 9.8 CVSS base score for network-vector, high-impact flaws). Successful exploitation gives the attacker control over switch configuration, with high confidentiality, integrity, and availability impact per the CVSS assessment. Affected parties are administrators running the cited model on RGOS 10.4(1)P2 Release 9736; the data provided lists no fixed version and does not confirm whether other RGOS releases are affected. There is no confirmed in-the-wild exploitation and the flaw is not in CISA KEV, but a public proof-of-concept exists and EPSS assigns a 28.4% probability of exploitation within 30 days (98th percentile), indicating elevated risk.
What to do: Identify any RG-NBS2009G-P switches running RGOS 10.4(1)P2 Release 9736 and verify whether system/config_menu.htm is reachable without authentication from untrusted networks; upgrade to a fixed Ruijie RGOS release (contact Ruijie support, as the advisory data lists no fixed version). Until patching, restrict access to the switch management interface with ACLs or a dedicated management VLAN and avoid exposing the web UI to the internet, and monitor logs for unauthenticated requests to system/config_menu.htm.
| Ruijie RG-NBS2009G-P switch firmware (RGOS) | RGOS 10.4(1)P2 Release 9736 (the version cited in the CVE; no other version ranges specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
- Vendors
- ruijie
- Products
- rg-nbs2009g-p firmware
- Weakness
- CWE-280
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.