CVE-2024-42936: Ruijie Reyee OS

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.

Affected products

  • Ruijie Reyee OS: version 1.300.1422 only

Published 2025-01-21. Last modified 2026-06-17.