CVE-2024-11654
PoC largeAuthenticated Command Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT
CVE-2024-11654 is a command injection flaw in the IPv6 traceroute diagnostic feature of three EnGenius wireless access points: ENH1350EXT, ENS500-AC and ENS620EXT. It is triggered by sending a manipulated diag_traceroute6 parameter to the /admin/network/diag_traceroute6 endpoint; per the CVSS 4.0 vector the attack is remote but requires high (administrator-level) privileges, and no user interaction is needed. Successful exploitation lets the attacker run arbitrary operating-system commands on the access point with the web interface's privileges, enabling device takeover, traffic manipulation or use as a pivot into the surrounding network. Anyone running affected firmware on these three models — all builds up to and including 20241118 — is exposed, and the vendor was contacted about the disclosure but did not respond, so no fix is confirmed in the available data. A public proof-of-concept exists, and the 29.1% EPSS score (98th percentile) indicates an elevated probability of exploitation attempts within 30 days, though the flaw is not yet in CISA's KEV catalog.
What to do: Inventory deployments of ENH1350EXT, ENS500-AC and ENS620EXT and check firmware builds, since everything up to and including 20241118 is affected and no patched release is documented because the vendor did not respond — monitor EnGenius support channels for a fix rather than assuming one is available. In the meantime, restrict the admin web interface to trusted management networks and harden/rotate administrator credentials, as the flaw requires admin access to trigger. Given the 29.1% EPSS (98th percentile), prioritize hardening and monitoring of any internet-facing units.
| EnGenius Technologies ENH1350EXT firmware | up to and including the 20241118 (Nov 18, 2024) build |
| EnGenius Technologies ENS500-AC firmware | up to and including the 20241118 (Nov 18, 2024) build |
| EnGenius Technologies ENS620EXT firmware | up to and including the 20241118 (Nov 18, 2024) build |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_traceroute6 leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.