CVE-2020-37015
Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal
CVSS Score
7.5
EPSS Score
0.5%
EPSS Percentile
66th
Ruijie Networks Switch eWeb S29_RGOS 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration files containing credentials and network settings.
| CWE | CWE-22 |
| Vendor | ruijienetworks |
| Product | ruijie networks switch eweb s29_rgos |
| Published | Jan 29, 2026 |
| Last Updated | May 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for ruijienetworks ruijie networks switch eweb s29_rgos
Be the first to know when new high vulnerabilities affecting ruijienetworks ruijie networks switch eweb s29_rgos are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Ruijienetworks / Ruijie Networks Switch eWeb S29_RGOS
eWeb S29_RGOS 11.4(1)B12P11
References
Credits
Tuygun