Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.
The product calls a function that can never be guaranteed to work safely.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Reyee_os | Ruijienetworks | 2.206.0 (including) | 2.320.0 (excluding) |