Vendor of the products: RUIJIE
Vendor's website: https://reyee.ruijie.com/en-global/
Reported by: smrx86
Affected products: RG-EW300N
Affected firmware version: ReyeeOS 1.300.1422
Affected Component:mqlink.elf services
Firmware download address: https://reyee.ruijie.com/en-global/resources/software/ew300n-firmware/ew300n-b11p300- firmware/
Fixed f/w: ReyeeOS 1.313.2406
RG-EW300N with f/w ReyeeOS 1.300.1422 have RCE vulnerability via intercept and modified MQTT broker message to run shell command.