CVE-2025-34057
Ruijie NBR Router Administrative Credential Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve administrative account credentials in plaintext. This flaw allows direct disclosure of sensitive user data due to improper authentication checks and insecure backend logic.
An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a specific POST request with modified Cookie headers and specially formatted parameters, an unauthenticated attacker can retrieve administrative account credentials in plaintext. This flaw allows direct disclosure of sensitive user data due to improper authentication checks and insecure backend logic.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-04-15 CVE Reserved
- 2025-07-02 CVE Published
- 2025-07-02 CVE Updated
- 2025-07-02 First Exploit
- 2025-07-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-306: Missing Authentication for Critical Function
CAPEC
- CAPEC-115: Authentication Bypass
References (3)
URL | Tag | Source |
---|---|---|
https://vulncheck.com/advisories/ruijie-nbr-router-administrative-credential-disclosure | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://vulners.com/seebug/SSV:89107 | 2025-07-02 | |
https://www.seebug.org/vuldb/ssvid-89107 | 2025-07-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ruijie Search vendor "Ruijie" | NBR Router Search vendor "Ruijie" for product "NBR Router" | 0 Search vendor "Ruijie" for product "NBR Router" and version "0" | en |
Affected
|