ZeroHour

CVE-2024-11653

PoC large

Command Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT Firmware

CVSS 4.0
5.1 medium
EPSS
29%p98
Published
()
Modified
AI analysis

CVE-2024-11653 is a command injection vulnerability in the traceroute diagnostic function of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access point firmware, with all builds up to and including 20241118 affected. A remote attacker who holds valid administrative credentials can inject operating system commands through the diag_traceroute argument of the /admin/network/diag_traceroute page, gaining command execution on the device. The CVSS v4.0 vector (AV:N/PR:H/UI:N) shows the attack is remote but requires high privileges (admin access), and the 5.1 (medium) score reflects limited confidentiality, integrity and availability impact, although the disclosing source rated the issue critical. EnGenius was contacted ahead of disclosure but did not respond, and no fixed firmware is confirmed in the available data. A public proof-of-concept is available, the flaw is not yet in CISA KEV, and EPSS assigns a 29.1% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

What to do: Inventory networks for ENH1350EXT, ENS500-AC and ENS620EXT units and check EnGenius for firmware newer than the 20241118 build, since no fixed version is confirmed and the vendor has been unresponsive. Until a patch is available, avoid exposing the devices' admin interface to the internet and limit administrative access to trusted operators, because exploitation requires valid admin credentials. Monitor for suspicious requests to /admin/network/diag_traceroute containing shell metacharacters or unexpected outbound activity from the APs.

Affected
EnGenius Technologies ENH1350EXT firmwareall versions up to and including 20241118
EnGenius Technologies ENS500-AC firmwareall versions up to and including 20241118
EnGenius Technologies ENS620EXT firmwareall versions up to and including 20241118
Estimated exposure
largetens of thousands of deployed access points (order-of-magnitude estimate, not vendor-reported) — These legacy EnGenius outdoor access points are commonly deployed in wireless-ISP and building-to-building/campus links, and public internet scans show EnGenius device management interfaces in the thousands-to-tens-of-thousands range, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. The manipulation of the argument diag_traceroute leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
engeniustech
Products
enh1350ext firmware, ens620ext firmware, ens500-ac firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.