CVE-2024-11653
PoC largeCommand Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT Firmware
CVE-2024-11653 is a command injection vulnerability in the traceroute diagnostic function of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access point firmware, with all builds up to and including 20241118 affected. A remote attacker who holds valid administrative credentials can inject operating system commands through the diag_traceroute argument of the /admin/network/diag_traceroute page, gaining command execution on the device. The CVSS v4.0 vector (AV:N/PR:H/UI:N) shows the attack is remote but requires high privileges (admin access), and the 5.1 (medium) score reflects limited confidentiality, integrity and availability impact, although the disclosing source rated the issue critical. EnGenius was contacted ahead of disclosure but did not respond, and no fixed firmware is confirmed in the available data. A public proof-of-concept is available, the flaw is not yet in CISA KEV, and EPSS assigns a 29.1% probability of exploitation within 30 days (98th percentile), indicating elevated risk.
What to do: Inventory networks for ENH1350EXT, ENS500-AC and ENS620EXT units and check EnGenius for firmware newer than the 20241118 build, since no fixed version is confirmed and the vendor has been unresponsive. Until a patch is available, avoid exposing the devices' admin interface to the internet and limit administrative access to trusted operators, because exploitation requires valid admin credentials. Monitor for suspicious requests to /admin/network/diag_traceroute containing shell metacharacters or unexpected outbound activity from the APs.
| EnGenius Technologies ENH1350EXT firmware | all versions up to and including 20241118 |
| EnGenius Technologies ENS500-AC firmware | all versions up to and including 20241118 |
| EnGenius Technologies ENS620EXT firmware | all versions up to and including 20241118 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. The manipulation of the argument diag_traceroute leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.