Ruijie Networks Switch eWeb S29_RGOS 11.4 contains a...
High severity
Unreviewed
Published
Jan 29, 2026
to the GitHub Advisory Database
•
Updated Jan 29, 2026
Description
Published by the National Vulnerability Database
Jan 29, 2026
Published to the GitHub Advisory Database
Jan 29, 2026
Last updated
Jan 29, 2026
Ruijie Networks Switch eWeb S29_RGOS 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration files containing credentials and network settings.
References