Vulnerability threat dossier

CVE-2023-4415

ruijienetworksrg-ew1200g

A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

VTP deterministic threat11.7of 100 · CVSS excluded

VTP analyst assessment

Ruijie RG-EW1200G improper authentication

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence70%
Public exploitation · VTP factUNKNOWN

Assessment

Ruijie RG-EW1200G firmware 07161417 r483 contains a remotely exploitable improper-authentication flaw in /api/sys/login. The description states that an exploit was publicly disclosed, while deterministic context reports no known exploit availability; exploit maturity is therefore unresolved. The supplied CVSS is 7.3 and EPSS is 0.58296, neither of which proves exploitation.

Why it matters

  • An unauthenticated remote attacker may bypass login controls, with confidentiality, integrity, and availability impact.
  • Public exploit disclosure in the description could lower practical barriers if confirmed.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The record conflicts on exploit availability and supplies no underlying source text to reconcile it.

No KEV entry, public-intelligence assertions, or first-party telemetry is supplied.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

Identify exposed RG-EW1200G devices running firmware 07161417 r483.

AI baseline history (1)
  1. BASELINE ASSESSED
    Ruijie RG-EW1200G improper authenticationgpt-5.6-sol · high
Technical severityHIGHCVSS 7.3 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.5899th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2023-4415. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 70/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2023-4415. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 70/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.58; this is predictive context, not exploitation evidence.

  2. 02

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

    05

    Original publications

    Source record

    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score11.7vtp-threat-v1-public
    Public exploitation0 / 30
    EPSS prediction11.66 / 20
    Exploit availability0 / 15
    Source independence0 / 15
    Intelligence recency0 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    7.3 · HIGH
    Vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
    CWE
    CWE-287
    CPE records
    2
    Deterministic history records
    20
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.