ZeroHour

CVE-2024-11652

PoC moderate

Command injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT AP firmware

CVSS 4.0
5.1 medium
EPSS
30%p98
Published
()
Modified
AI analysis

EnGenius firmware for the ENH1350EXT, ENS500-AC and ENS620EXT outdoor access points, in versions up to and including the 20241118 (2024-11-18) build, contains a command-injection flaw (CWE-74/CWE-77) in the web management interface at /admin/sn_package/sn_https. A remote attacker who can reach that endpoint and holds high-privilege (administrative) credentials, per the CVSS 4.0 PR:H metric, can submit a manipulated https_enable parameter to inject operating-system commands on the device. Successful exploitation yields remote command execution, although the CVSS 4.0 impact metrics rate the resulting effect on confidentiality, integrity and availability as low. Any organization running these three EnGenius AP models with a reachable management interface is affected, with internet-exposed or remote-management-enabled deployments at greatest risk. A proof-of-concept exploit has already been published, EPSS assigns a 30.2% probability of exploitation within 30 days (98th percentile), the issue is not yet in CISA KEV, and the vendor was notified early but did not respond, so no fixed firmware is confirmed in the available data.

What to do: Because the vendor did not respond to the disclosure and no fixed firmware version appears in the available data, check EnGenius support channels for updated firmware for these three models and apply it when released. Until then, restrict access to the web management interface (/admin) to trusted networks or VPN rather than exposing it to the internet, and ensure strong administrator credentials are in use. Review device or reverse-proxy access logs for requests to /admin/sn_package/sn_https with unexpected https_enable values as indicators of probing or exploitation.

Affected
EnGenius Technologies ENH1350EXT firmwareall versions up to and including 20241118 (2024-11-18 build); no fixed version identified in available data
EnGenius Technologies ENS500-AC firmwareall versions up to and including 20241118 (2024-11-18 build); no fixed version identified in available data
EnGenius Technologies ENS620EXT firmwareall versions up to and including 20241118 (2024-11-18 build); no fixed version identified in available data
Estimated exposure
moderate~1,000-10,000 affected devices (total deployed units likely in the low tens of thousands; internet-exposed admin interfaces likely a smaller subset) — No public install-base counts or internet-exposure scan data exist for these three older EnGenius outdoor AP models, so the estimate is based on the niche business-Wi-Fi/WISP deployment segment of these devices and the common practice of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_https. The manipulation of the argument https_enable leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
engeniustech
Products
enh1350ext firmware, ens500-ac firmware, ens620ext firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.