CVE-2023-53881

Severity CVSS v4.0:
CRITICAL
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
15/12/2025
Last modified:
18/12/2025

Description

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ruijienetworks:reyee_os:1.204.1614:*:*:*:*:*:*:*