216.73.216.6

CVE-2023-53881

· Published 15/12/2025 21:15 · Modified 18/12/2025 22:38

Labels: CVE-2023-53881 2025-12-15CVE-2023-53881[email protected]

Essential information

Published
15/12/2025 21:15
Modified
18/12/2025 22:38
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ruijienetworks / reyee os cpe:2.3:o:ruijienetworks:reyee_os:1.204.1614:*:*:*:*:*:*:*

References