← Vulnerability feed

Vulnerability record · CVE-2024-47547 · published 6 December 2024

CVE-2024-47547: Ruijienetworks reyee os weak password recovery vulnerability

Ruijienetworks · Reyee Os

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.

9.3 CVSS 4.0 Critical EPSS 0.67% · top 49.9% CWE-640 · Weak password recovery
9.3CVSS 4.0 base score
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01 Third Party AdvisoryUS Government Resource

Track CVE-2024-47547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2024-48874Ruijienetworks reyee os server-side request forgery (ssrf) vulnerabilityRuijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any requ…EPSS 0.60%9.2CVE-2023-53881Ruijienetworks reyee os cleartext transmission vulnerabilityReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication th…EPSS 0.31%9.2CVE-2024-52324Ruijienetworks reyee os vulnerabilityRuijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malici…EPSS 0.69%9.2CVE-2024-46874Ruijienetworks reyee os vulnerabilityRuijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some…EPSS 0.40%8.8CVE-2025-56077Ruijienetworks reyee os os command injection vulnerabilityOS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to th…EPSS 2.8%8.7CVE-2024-45722Ruijienetworks reyee os vulnerabilityRuijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT…EPSS 0.46%8.7CVE-2024-47791Ruijienetworks reyee os vulnerabilityRuijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broke…EPSS 0.39%8.7CVE-2024-47043Ruijienetworks reyee os vulnerabilityRuijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone nu…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2024-47547), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.