Security Advisory

CVE-2020-37015

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-29 14:28:32
Last updated 2026-01-29 15:14:28
Assigner VulnCheck
State PUBLISHED

Description

Ruijie Networks Switch eWeb S29_RGOS 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with ../ sequences to retrieve system configuration files containing credentials and network settings.