漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ruijie NBR Router Administrative Credential Disclosure
Vulnerability Description
An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve administrative account credentials in plaintext. This flaw allows direct disclosure of sensitive user data due to improper authentication checks and insecure backend logic. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
CVSS Information
N/A
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Ruijie NBR Router 安全漏洞
Vulnerability Description
Ruijie NBR Router是中国锐捷(Ruijie)公司的一款无线路由器。 Ruijie NBR Router存在安全漏洞,该漏洞源于认证检查不当,可能导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A