← back
CVE-2023-7304criticalobserved exploitationCWE-78

Ruijie RG-UAC nmc_sync.php Command Injection

70Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.3epss 3.6%
from disclosure to weapon
Published on NVDOct 15
VulnCheckOct 14
exploitation probability
3.6%top 11% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute arbitrary commands on the host. Successful exploitation can yield full control of the application process and may lead to system-level access depending on the service privileges. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.