ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Vulnerabilities Exposed - CVE-2024-52324, CVE-2024-48874, and CVE-2024-47547

Paul by Paul
December 25, 2024
in Exploits
Reading Time: 2 mins read
Claroty reveals 10 critical vulnerabilities in Ruijie Networks' cloud platform, exposing massive security risks for 50,000 network devices worldwide.
Share on FacebookShare on Twitter

Cybersecurity experts have revealed a series of alarming vulnerabilities in Ruijie Networks’ cloud management platform that could potentially compromise tens of thousands of network devices. Researchers from Claroty have discovered a stunning array of security flaws that could allow malicious actors to gain unprecedented access to network infrastructure.

The Vulnerability

The investigation uncovered 10 critical security vulnerabilities, with three standing out as particularly dangerous:

  • CVE-2024-47547: A weak password recovery mechanism vulnerable to brute force attacks
  • CVE-2024-48874: A server-side request forgery (SSRF) vulnerability exposing internal cloud infrastructure
  • CVE-2024-52324: A critical flaw allowing arbitrary operating system command execution

The “Open Sesame” Attack

Perhaps most concerning is the researchers’ development of an attack method dubbed “Open Sesame” (CVE-2024-47146). This sophisticated technique allows attackers in close physical proximity to intercept Wi-Fi beacons and extract device serial numbers, potentially leading to remote code execution.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

Authentication and Access Risks

The research revealed a particularly troubling authentication vulnerability. By simply knowing a device’s serial number, attackers could:

  • Break MQTT authentication
  • Generate valid authentication credentials
  • Perform denial-of-service attacks
  • Send fabricated messages to cloud-connected devices

Potential Impact

Approximately 50,000 cloud-connected devices were potentially impacted by these security flaws. The vulnerabilities could have allowed attackers to:

  1. Execute arbitrary commands
  2. Disconnect devices
  3. Send false data to users
  4. Gain unauthorized network access

Resolution and Mitigation

Fortunately, Ruijie Networks has addressed these vulnerabilities following responsible disclosure. No additional user action is required, but the discovery highlights ongoing cybersecurity challenges in Internet of Things (IoT) devices.

“This is another example of the low barrier to entry for attackers in connected devices,” the Claroty researchers noted, emphasizing the critical nature of continuous security monitoring.

Previous Post

Google’s Controversial Ad Tracking Move Sparks Privacy Concerns

Next Post

Chinese State Hackers Breach US Treasury Department Through Cybersecurity Vendor

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

CISA Adds Critical Microsoft SharePoint Vulnerability (CVE-2024-38094) to Known Exploited Vulnerabilities Catalog

October 23, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.