Ruijie vendor intelligence
Ruijie Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Ruijie products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 6
- Known exploited vulnerabilities affecting Ruijie products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 6
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Ruijie KEVs with sensor-observed exploitation activity
The catalog gap matters for Ruijie exposure
Six of the six exploited Ruijie CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 6
- Product families
Attested Ruijie CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-36870
Ruijie Gateway EG & NBR Models v11.1(6)B9P1 - 11.9(4)B12P1 RCE |
RG-EG1000C, RG-EG2000F, RG-EG2000K, RG-EG2000L, RG-EG2000CE, RG-EG2000SE, RG-EG2000GE, RG-EG2000XE, RG-EG2000UE, RG-EG3000CE, RG-EG3000SE, RG-EG3000GE, RG-EG3000ME, RG-EG3000UE, RG-EG3000XE, RG-EG2100-P, EG3210, EG3220, EG3230, EG3250, NBR108G-P, NBR1000G-E, NBR1300G-E, NBR1700G-E, NBR2100G-E, NBR2500D-E, NBR3000D-E, NBR6120-E, NBR6135-E, NBR6205-E, NBR6210-E, NBR6215-E, NBR800G, NBR950G, NBR1000G-C, NBR2000G-C, NBR3000G-S | High | Beyond CISA | 24 Jan 2026 |
|
CVE-2025-34057
Ruijie NBR Router Administrative Credential Disclosure |
NBR Router | High | Beyond CISA | 10 Jan 2026 |
|
CVE-2023-4169
Ruijie RG-EW1200G Administrator Password set_passwd access control |
RG-EW1200G | High | Beyond CISA | 26 Nov 2025 |
|
CVE-2023-7304
Ruijie RG-UAC nmc_sync.php Command Injection |
RG-UAC | High | Beyond CISA | 29 Nov 2025 |
|
CVE-2023-3608
Ruijie BCR810W Tracert Page os command injection |
BCR810W | High | Beyond CISA | 10 Jul 2023 |
|
CVE-2021-43163
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the... |
Ruijie RG-EW Series Routers | High | Beyond CISA | 04 May 2022 |
No Ruijie CVEs match this search or filter.
Showing 6 of 6 Ruijie known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, access control, and missing authentication for critical function account for four mapped occurrences across this Ruijie KEV portfolio.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-284
Improper Access Control
CWE-306
Missing Authentication for Critical Function
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-94
Improper Control of Generation of Code ('Code Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.