Use of Inherently Dangerous Function
CVE-2024-52324
Summary
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-242 - Use of Inherently Dangerous Function
The program calls a function that can never be guaranteed to work safely.
References
Advisory Timeline
- Published