ZeroHour

CVE-2024-11654

PoC large

Authenticated Command Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT

CVSS 4.0
5.1 medium
EPSS
29%p98
Published
()
Modified
AI analysis

CVE-2024-11654 is a command injection flaw in the IPv6 traceroute diagnostic feature of three EnGenius wireless access points: ENH1350EXT, ENS500-AC and ENS620EXT. It is triggered by sending a manipulated diag_traceroute6 parameter to the /admin/network/diag_traceroute6 endpoint; per the CVSS 4.0 vector the attack is remote but requires high (administrator-level) privileges, and no user interaction is needed. Successful exploitation lets the attacker run arbitrary operating-system commands on the access point with the web interface's privileges, enabling device takeover, traffic manipulation or use as a pivot into the surrounding network. Anyone running affected firmware on these three models — all builds up to and including 20241118 — is exposed, and the vendor was contacted about the disclosure but did not respond, so no fix is confirmed in the available data. A public proof-of-concept exists, and the 29.1% EPSS score (98th percentile) indicates an elevated probability of exploitation attempts within 30 days, though the flaw is not yet in CISA's KEV catalog.

What to do: Inventory deployments of ENH1350EXT, ENS500-AC and ENS620EXT and check firmware builds, since everything up to and including 20241118 is affected and no patched release is documented because the vendor did not respond — monitor EnGenius support channels for a fix rather than assuming one is available. In the meantime, restrict the admin web interface to trusted management networks and harden/rotate administrator credentials, as the flaw requires admin access to trigger. Given the 29.1% EPSS (98th percentile), prioritize hardening and monitoring of any internet-facing units.

Affected
EnGenius Technologies ENH1350EXT firmwareup to and including the 20241118 (Nov 18, 2024) build
EnGenius Technologies ENS500-AC firmwareup to and including the 20241118 (Nov 18, 2024) build
EnGenius Technologies ENS620EXT firmwareup to and including the 20241118 (Nov 18, 2024) build
Estimated exposure
large≈tens of thousands of installed devices across the three models (order-of-magnitude); the internet-exposed subset is unknown — No install counts were provided in the data; the estimate reflects that these are three older EnGenius outdoor/enterprise Wi-Fi AP models historically deployed in volume by WISPs, campuses and outdoor venues, of which only a fraction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_traceroute6 leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
engeniustech
Products
enh1350ext firmware, ens620ext firmware, ens500-ac firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.