CVE Feed

    Dashboard / CVE / CVE-2020-36870

    CVE-2020-36870

    Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code when features such as guest authentication, local server authentication, or screen mirroring are enabled to gain access or execute commands on affected devices. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-05 UTC.

    Published:Nov 7, 2025
    Last Modified:Apr 15, 2026
    EPS:Nov 7, 2025
    EPSS Score:0.00103
    CVSS Score:9.2

    Affected Products

    Vendor
    Ruijie
    Product
    Eg3210
    Vendor
    Ruijie
    Product
    Eg3220
    Vendor
    Ruijie
    Product
    Eg3230
    Vendor
    Ruijie
    Product
    Eg3250
    Vendor
    Ruijie
    Product
    Nbr1000g-c
    Vendor
    Ruijie
    Product
    Nbr1000g-e
    Vendor
    Ruijie
    Product
    Nbr108g-p
    Vendor
    Ruijie
    Product
    Nbr1300g-e
    Vendor
    Ruijie
    Product
    Nbr1700g-e
    Vendor
    Ruijie
    Product
    Nbr2000g-c
    Vendor
    Ruijie
    Product
    Nbr2100g-e
    Vendor
    Ruijie
    Product
    Nbr2500d-e
    Vendor
    Ruijie
    Product
    Nbr3000d-e
    Vendor
    Ruijie
    Product
    Nbr3000g-s
    Vendor
    Ruijie
    Product
    Nbr6120-e
    Vendor
    Ruijie
    Product
    Nbr6135-e
    Vendor
    Ruijie
    Product
    Nbr6205-e
    Vendor
    Ruijie
    Product
    Nbr6210-e
    Vendor
    Ruijie
    Product
    Nbr6215-e
    Vendor
    Ruijie
    Product
    Nbr800g
    Vendor
    Ruijie
    Product
    Nbr950g
    Vendor
    Ruijie
    Product
    Rg-eg1000c
    Vendor
    Ruijie
    Product
    Rg-eg2000ce
    Vendor
    Ruijie
    Product
    Rg-eg2000f
    Vendor
    Ruijie
    Product
    Rg-eg2000ge
    Vendor
    Ruijie
    Product
    Rg-eg2000k
    Vendor
    Ruijie
    Product
    Rg-eg2000l
    Vendor
    Ruijie
    Product
    Rg-eg2000se
    Vendor
    Ruijie
    Product
    Rg-eg2000ue
    Vendor
    Ruijie
    Product
    Rg-eg2000xe
    Vendor
    Ruijie
    Product
    Rg-eg2100-p
    Vendor
    Ruijie
    Product
    Rg-eg3000ce
    Vendor
    Ruijie
    Product
    Rg-eg3000ge
    Vendor
    Ruijie
    Product
    Rg-eg3000me
    Vendor
    Ruijie
    Product
    Rg-eg3000se
    Vendor
    Ruijie
    Product
    Rg-eg3000ue
    Vendor
    Ruijie
    Product
    Rg-eg3000xe
    Vendor
    Ruijie
    Product
    Rg-eg3230
    Vendor
    Ruijie
    Product
    Rg-eg3250
    Vendor
    Ruijie
    Product
    Rg-nbr6120-e
    Vendor
    Ruijie
    Product
    Rg-nbr6205-e
    Vendor
    Ruijie
    Product
    Rg-nbr6210-e
    Vendor
    Ruijie
    Product
    Rg-nbr6215-e
    Vendor
    Ruijienetworks
    Product
    Rg-nbr2100g-e

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High