CVE-2024-11655
PoC largeCommand Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT Firmware
CVE-2024-11655 is a remote command injection flaw (CWE-74/CWE-77) in the web management interface of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access-point firmware, in the diag_ping parameter of /admin/network/diag_pinginterface. An attacker who sends a crafted diag_ping value to that endpoint causes the device to execute arbitrary operating-system commands; the published CVSS 4.0 vector (PR:H) indicates the request must come from a high-privilege administrator session, which is why the vector scores 5.1 (medium) even though the reporting CNA classifies the flaw as critical. Command execution on these embedded access points typically lets an attacker reconfigure the device, tamper with traffic on the networks it bridges, or move laterally into the connected networks. All firmware builds dated 20241118 or earlier on the three models are affected; the vendor was notified early about the disclosure but did not respond, and no fixed version is identified in the available data. A public proof of concept has been published (https://k9u7kv33ub.feishu.cn/wiki/PpM6w3TF8ilK3Ek5RLqcLPUrn6c), the flaw is not yet in CISA KEV, and EPSS assigns a 28.8% probability (98th percentile) of exploitation within 30 days, so defenders should treat exploitation as likely.
What to do: Inventory environments for ENH1350EXT, ENS500-AC and ENS620EXT access points and restrict the management interface to trusted networks (management VLAN/VPN, WAN-side management disabled) until a fixed firmware is released, since the vendor has not yet published one and affected builds run through 20241118. Use the public PoC to hunt for signs of exploitation, such as unexpected diagnostic ping activity or unexplained configuration changes, and monitor for a vendor advisory or updated firmware.
| EnGenius ENH1350EXT firmware | All firmware up to 20241118; no fixed version identified in the available data |
| EnGenius ENS500-AC firmware | All firmware up to 20241118; no fixed version identified in the available data |
| EnGenius ENS620EXT firmware | All firmware up to 20241118; no fixed version identified in the available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_ping leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.