CVE-2024-47791
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, and receive partial messages being sent to and from devices.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-155
- Published
- 2024-12-06
- Last modified
- 2026-03-13
Affected products
- Ruijie Reyee OS
Weakness type
Related vulnerabilities
- CVE-2026-87016 — Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
- CVE-2026-68939 — Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)
- CVE-2026-73412 — Shescape: Path disclosure on Unix with Zsh
- CVE-2026-49482 — ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
- CVE-2025-11757 — Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App
- CVE-2025-4232 — GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
- CVE-2025-27515 — Laravel has a File Validation Bypass
- CVE-2025-0681 — New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols