Skip to main content

Use of Inherently Dangerous Function

CVE-2024-52324

Severity High
Score 9.2/10

Summary

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-242 - Use of Inherently Dangerous Function

The program calls a function that can never be guaranteed to work safely.

References

Advisory Timeline

  • Published