Ruijie's vulnerability footprint spans a substantial portfolio of network security and access-control appliances, predominantly centered on its UAC (Unified Access Control) product line, which occupies a prominent position in enterprise network infrastructure deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged access and control-plane exposure inherent to security gateway and authentication appliances. The exposure recurs across firmware and hardware variants of the UAC 6000 series through weakness classes including OS command injection, command injection, improper access control, and code injection—attack vectors typical of network appliances that parse and execute administrative input or system commands. Defenders should prioritize patching and network segmentation for these appliances given their position in security-critical infrastructure and the severity profile of disclosed flaws. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ruijie over time
Signals from CVEs in this vendor scope (116 CVEs).
116 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4415HIGH A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The ma | Aug 18, 2023 | 8.8 | 70 | NO | YES |
CVE-2023-4169HIGH A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/sys/set_pas | Aug 5, 2023 | 8.8 | 62 | NO | YES |
CVE-2021-43164HIGH A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-b | May 4, 2022 | 8.8 | 61 | NO | YES |
CVE-2024-24116CRITICAL An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. | Oct 2, 2024 | 9.8 | 53 | NO | YES |
CVE-2023-3450HIGH A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulati | Jun 28, 2023 | 7.2 | 47 | NO | NO |
CVE-2025-9424CRITICAL A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch_import.php?a=branch_list. Such | Aug 25, 2025 | 9.8 | 44 | NO | NO |
CVE-2023-3306CRITICAL A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the file app.09df2a9e44ab48766f5f.js o | Jun 18, 2023 | 9.8 | 40 | NO | NO |
CVE-2025-56752CRITICAL A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted acce | Sep 3, 2025 | 9.4 | 33 | NO | NO |
CVE-2021-43163CRITICAL A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/lu | May 4, 2022 | 9.8 | 33 | NO | NO |
CVE-2024-4815CRITICAL A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240506. Affected by this issue is some unknown functionality of the file /view/bugSolve/v | May 14, 2024 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (116 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ruijie.
Media articles that mention a CVE ID that affects a product developed by Ruijie — matched by CVE ID, not by vendor name.