ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.
References
| Link | Resource |
|---|---|
| https://ruijienetworks.com | Product Broken Link |
| https://www.exploit-db.com/exploits/51642 | Exploit |
| https://www.vulncheck.com/advisories/reyeeos-man-in-the-middle-remote-code-execution-via-cwmp | Third Party Advisory |
Configurations
History
18 Dec 2025, 22:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://ruijienetworks.com - Product, Broken Link | |
| References | () https://www.exploit-db.com/exploits/51642 - Exploit | |
| References | () https://www.vulncheck.com/advisories/reyeeos-man-in-the-middle-remote-code-execution-via-cwmp - Third Party Advisory | |
| First Time |
Ruijienetworks
Ruijienetworks reyee Os |
|
| CPE | cpe:2.3:o:ruijienetworks:reyee_os:1.204.1614:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
15 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-15 21:15
Updated : 2025-12-18 22:38
NVD link : CVE-2023-53881
Mitre link : CVE-2023-53881
CVE.ORG link : CVE-2023-53881
JSON object : View
Products Affected
ruijienetworks
- reyee_os
CWE
CWE-319
Cleartext Transmission of Sensitive Information
