CVE-2024-11651
PoC moderateCommand Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT Access Points
CVE-2024-11651 is a command injection vulnerability (CWE-77) in the web management interface of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT firmware up to and including the 20241118 build. An attacker triggers it by submitting a crafted value in the wifi_schedule_day_em_5 parameter to the /admin/network/wifi_schedule endpoint, where it is passed to an OS shell without sanitization; the attack is launched remotely, and the CVSS 4.0 vector indicates administrator-level privileges are required. Successful injection allows execution of arbitrary OS commands on the access point, giving the attacker control over the device and a potential foothold in the network it serves, though CVSS 4.0 rates the direct impact as low. Any deployment of these three legacy EnGenius outdoor/business access points running firmware dated 20241118 or earlier is affected, with the highest risk on devices whose admin interface is internet-reachable or that use default or shared admin credentials. A public proof-of-concept has been disclosed, the vendor was contacted before disclosure but did not respond, and EPSS assigns a 27.4% probability of exploitation within 30 days (98th percentile), though the flaw is not yet in CISA's KEV and no confirmed in-the-wild exploitation is documented.
What to do: No fixed firmware version is confirmed in available data and the vendor did not respond at disclosure, so verify your model and firmware date (20241118 or earlier means affected) and check EnGenius support channels for an updated release. In the meantime, restrict each device's management interface to a trusted management VLAN or VPN rather than the internet, and eliminate default or shared admin credentials since administrator privileges are required for exploitation. Treat these as legacy devices and evaluate replacement if no patched firmware appears.
| engeniustech ENH1350EXT firmware | up to and including 20241118 (date-stamped firmware; no fixed release known) |
| engeniustech ENS500-AC firmware | up to and including 20241118 (date-stamped firmware; no fixed release known) |
| engeniustech ENS620EXT firmware | up to and including 20241118 (date-stamped firmware; no fixed release known) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of the file /admin/network/wifi_schedule. The manipulation of the argument wifi_schedule_day_em_5 leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.