CVE-2023-7330 is an unauthenticated arbitrary file upload vulnerability affecting Ruijie NBR series routers, specifically via the /ddi/server/fileupload.php endpoint. Attackers can leverage inadequate validation of file type, path, and extension to upload malicious PHP files. This critical vulnerability, with a CVSS score of 9.3, allows for remote arbitrary code execution in the context of the web service. While exploitation evidence was observed by the Shadowserver Foundation on January 14, 2025, there is currently no public exploit code available, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Beijing Star-Net Ruijie Network Technology Co., Ltd. | NBR Series Routers | 0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.