Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-14 UTC.
History

Tue, 25 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijie
Ruijie rg-nbr*
CPEs cpe:2.3:h:ruijie:rg-nbr*:-:*:*:*:*:*:*:*
Vendors & Products Ruijie
Ruijie rg-nbr*

Mon, 24 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
Description Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-14 UTC.
Title Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-11-24T20:31:19.914Z

Updated: 2025-11-25T13:04:06.622Z

Reserved: 2025-11-24T19:18:42.972Z

Link: CVE-2023-7330

cve-icon Vulnrichment

Updated: 2025-11-24T21:06:23.962Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-24T21:16:01.460

Modified: 2025-11-25T22:16:16.690

Link: CVE-2023-7330

cve-icon Redhat

No data.