CVE-2020-37015

Publication date

2026-01-29 14:28:32

Family

VulnCheck

State

PUBLISHED

Description

Ruijie Networks Switch eWeb S29_RGOS 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with ../ sequences to retrieve system configuration files containing credentials and network settings.