Vulnerability record · CVE-2023-4169 · published 5 August 2023
CVE-2023-4169: Ruijie RG-EW1200G router password endpoint improper access control
Ruijie · Rg Ew1200g Firmware
The Ruijie RG-EW1200G firmware 1.0(1)B1P5 exposes the /api/sys/set_passwd administrator password handler without proper access control, allowing a remote attacker to change the admin password. The vendor did not respond to the disclosure, so no fixed firmware is known and the flaw is publicly exploitable.
Description
A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/sys/set_passwd of the component Administrator Password Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236185 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with public exploit code and very high EPSS, but exploitation requires low privileges and no KEV listing, so it is high rather than critical.
What it is
The Ruijie RG-EW1200G firmware 1.0(1)B1P5 exposes the /api/sys/set_passwd administrator password handler without proper access control, allowing a remote attacker to change the admin password. The vendor did not respond to the disclosure, so no fixed firmware is known and the flaw is publicly exploitable.
Impact
An attacker can rewrite the administrator password and take over the device's management interface, gaining full control of the router's configuration and traffic handling.
Attack surface
Reachable over the network via the web API endpoint /api/sys/set_passwd; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N), so the attacker needs some authenticated or low-privilege access to the device interface.
Exploitation
A public exploit is referenced on GitHub, EPSS is 0.4923 (98.8th percentile), and the CVE is not listed in CISA KEV, indicating active public exploit code but no confirmed widespread exploitation.
What to do
- Apply any vendor firmware update for RG-EW1200G if one becomes available; the vendor did not respond to the disclosure, so confirm with Ruijie support.
- If no patch exists, restrict access to the router's web management interface to trusted networks only and disable remote/WAN administration.
- Change default administrator credentials and enforce strong unique passwords on all management accounts.
- Segment or isolate the router from sensitive networks and monitor for unauthorized configuration changes.
- Consider replacing the device if the vendor remains unresponsive and no fix is provided.
Detection
- Monitor router and web logs for POST requests to /api/sys/set_passwd, especially from unexpected source IPs.
- Alert on administrator password change events or authentication failures followed by successful logins.
- Watch for configuration changes or new admin accounts on RG-EW1200G devices outside change windows.
- Use network monitoring to detect management interface access from untrusted or external networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/blakespire/repoforcve/tree/main/RG-EW1200G | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.236185 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.236185 | Permissions RequiredThird Party Advisory |
| https://github.com/blakespire/repoforcve/tree/main/RG-EW1200G | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.236185 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.236185 | Permissions RequiredThird Party Advisory |
Track CVE-2023-4169 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-4169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.