CVE-2020-37015: Ruijienetworks Ruijie Networks Switch Eweb s29 Rgos

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration files containing credentials and network settings.

Affected products

Published 2026-01-29. Last modified 2026-06-17.