Security Advisory
CVE-2020-37015
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Ruijie Networks Switch eWeb S29_RGOS 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with ../ sequences to retrieve system configuration files containing credentials and network settings.