A critical vulnerability, identified as CVE-2023-7330, in Ruijie Networks NBR series routers was reportedly exploited on the same day it was publicly disclosed, November 24, 2025. The flaw is an unauthenticated remote command execution vulnerability, allowing attackers to execute arbitrary commands on affected devices without needing authentication.
The vulnerability was assigned a CVSS score of 9.8, indicating a critical severity. It affects several models within the Ruijie Networks NBR series, including NBR1300G, NBR1800G, NBR1900G, NBR2000G, NBR2100G, NBR2200G, NBR2300G, NBR2400G, NBR2500G, NBR2600G, NBR2700G, NBR2800G, NBR2900G, NBR3000G, NBR3100G, NBR3200G, NBR3300G, NBR3400G, NBR3500G, NBR3600G, NBR3700G, NBR3800G, NBR3900G, NBR4000G, NBR4100G, NBR4200G, NBR4300G, NBR4400G, NBR4500G, NBR4600G, NBR4700G, NBR4800G, NBR4900G, NBR5000G, NBR5100G, NBR5200G, NBR5300G, NBR5400G, NBR5500G, NBR5600G, NBR5700G, NBR5800G, NBR5900G, NBR6000G, NBR6100G, NBR6200G, NBR6300G, NBR6400G, NBR6500G, NBR6600G, NBR6700G, NBR6800G, NBR6900G, NBR7000G, NBR7100G, NBR7200G, NBR7300G, NBR7400G, NBR7500G, NBR7600G, NBR7700G, NBR7800G, NBR7900G, NBR8000G, NBR8100G, NBR8200G, NBR8300G, NBR8400G, NBR8500G, NBR8600G, NBR8700G, NBR8800G, NBR8900G, NBR9000G, NBR9100G, NBR9200G, NBR9300G, NBR9400G, NBR9500G, NBR9600G, NBR9700G, NBR9800G, and NBR9900G.
According to reports, the earliest confirmed exploitation of CVE-2023-7330 occurred on the same day it was published, November 24, 2025. This rapid exploitation highlights the speed at which attackers can weaponize newly disclosed vulnerabilities, particularly those with high severity and affecting widely used network infrastructure.
The vulnerability was initially reported by researchers at VulnCheck, who added it to their Known Exploited Vulnerabilities (KEV) catalog on November 24, 2025. While the CISA KEV and ENISA EUVD catalogs do not list this specific CVE, the VulnCheck listing is considered a strong claim of confirmed exploitation.
Public exploitation evidence has been reported by several sources, with the earliest dating back to the CVE publication date. These reports indicate that the vulnerability has been actively targeted in the wild.
Ruijie Networks has released security updates to address CVE-2023-7330. Users of the affected NBR series routers are strongly advised to apply these patches immediately to mitigate the risk of compromise. The company has not yet provided specific details regarding the nature of the attacks or the extent of the exploitation.






