logo

The Insecure IoT Cloud Strikes Again: RCE on Ruijie Cloud-Connected Devices

ID: 5d4fd7f0-c159-5849-9a53-7654bbeb4684

STIX ID: report--5d4fd7f0-c159-5849-9a53-7654bbeb4684

Feed Name: Claroty Team82

Threat Score
78/100

Date Published: 2024-12-09

Date Updated: 2026-04-17

Author: Noam Moshe; Tomer Goldschmidt

...
...

Team82 disclosed ten vulnerabilities in Ruijie Networks' Reyee cloud platform and Reyee OS devices that allow an attacker to obtain remote code execution on cloud‑connected access points by leveraging serial-number-based credentials, MQTT authentication weaknesses and broker wildcard behavior; an attacker can mass-target devices or perform a localized "Open Sesame" attack by sniffing serial numbers from Wi‑Fi beacons to gain internal network access. Ruijie has reportedly addressed the vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.