CVE-2019-16640 describes an arbitrary file upload vulnerability in the upload.php component of Ruijie EG-2000 series gateways, specifically affecting EG-2000SE EG_RGOS 11.9 B11P1. This flaw, rated 7.5 HIGH on the CVSS scale, allows an unauthenticated attacker to upload any file to the gateway due to improper handling of parameters passed to the UploadFile class. While the vulnerability presents a significant integrity risk (I:H), there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1\(1\)b1CPE matchmatch criteria | cpe:2.3:o:ruijie:eg-2000se_firmware:11.1\(1\)b1:*:*:*:*:*:*:* | ||
11.9_b11p1CPE matchmatch criteria | cpe:2.3:o:ruijie:eg-2000se_firmware:11.9_b11p1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.