Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-14 UTC.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ruijie
Ruijie rg-nbr* |
|
| CPEs | cpe:2.3:h:ruijie:rg-nbr*:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Ruijie
Ruijie rg-nbr* |
Mon, 24 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-14 UTC. | |
| Title | Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php | |
| Weaknesses | CWE-434 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-24T20:31:19.914Z
Updated: 2025-11-25T13:04:06.622Z
Reserved: 2025-11-24T19:18:42.972Z
Link: CVE-2023-7330
Updated: 2025-11-24T21:06:23.962Z
Status : Awaiting Analysis
Published: 2025-11-24T21:16:01.460
Modified: 2025-11-25T22:16:16.690
Link: CVE-2023-7330
No data.