CVE-2024-11652
PoC moderateCommand injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT AP firmware
EnGenius firmware for the ENH1350EXT, ENS500-AC and ENS620EXT outdoor access points, in versions up to and including the 20241118 (2024-11-18) build, contains a command-injection flaw (CWE-74/CWE-77) in the web management interface at /admin/sn_package/sn_https. A remote attacker who can reach that endpoint and holds high-privilege (administrative) credentials, per the CVSS 4.0 PR:H metric, can submit a manipulated https_enable parameter to inject operating-system commands on the device. Successful exploitation yields remote command execution, although the CVSS 4.0 impact metrics rate the resulting effect on confidentiality, integrity and availability as low. Any organization running these three EnGenius AP models with a reachable management interface is affected, with internet-exposed or remote-management-enabled deployments at greatest risk. A proof-of-concept exploit has already been published, EPSS assigns a 30.2% probability of exploitation within 30 days (98th percentile), the issue is not yet in CISA KEV, and the vendor was notified early but did not respond, so no fixed firmware is confirmed in the available data.
What to do: Because the vendor did not respond to the disclosure and no fixed firmware version appears in the available data, check EnGenius support channels for updated firmware for these three models and apply it when released. Until then, restrict access to the web management interface (/admin) to trusted networks or VPN rather than exposing it to the internet, and ensure strong administrator credentials are in use. Review device or reverse-proxy access logs for requests to /admin/sn_package/sn_https with unexpected https_enable values as indicators of probing or exploitation.
| EnGenius Technologies ENH1350EXT firmware | all versions up to and including 20241118 (2024-11-18 build); no fixed version identified in available data |
| EnGenius Technologies ENS500-AC firmware | all versions up to and including 20241118 (2024-11-18 build); no fixed version identified in available data |
| EnGenius Technologies ENS620EXT firmware | all versions up to and including 20241118 (2024-11-18 build); no fixed version identified in available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_https. The manipulation of the argument https_enable leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens500-ac firmware, ens620ext firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.