ZeroHour

CVE-2024-11655

PoC large

Command Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT Firmware

CVSS 4.0
5.1 medium
EPSS
29%p98
Published
()
Modified
AI analysis

CVE-2024-11655 is a remote command injection flaw (CWE-74/CWE-77) in the web management interface of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access-point firmware, in the diag_ping parameter of /admin/network/diag_pinginterface. An attacker who sends a crafted diag_ping value to that endpoint causes the device to execute arbitrary operating-system commands; the published CVSS 4.0 vector (PR:H) indicates the request must come from a high-privilege administrator session, which is why the vector scores 5.1 (medium) even though the reporting CNA classifies the flaw as critical. Command execution on these embedded access points typically lets an attacker reconfigure the device, tamper with traffic on the networks it bridges, or move laterally into the connected networks. All firmware builds dated 20241118 or earlier on the three models are affected; the vendor was notified early about the disclosure but did not respond, and no fixed version is identified in the available data. A public proof of concept has been published (https://k9u7kv33ub.feishu.cn/wiki/PpM6w3TF8ilK3Ek5RLqcLPUrn6c), the flaw is not yet in CISA KEV, and EPSS assigns a 28.8% probability (98th percentile) of exploitation within 30 days, so defenders should treat exploitation as likely.

What to do: Inventory environments for ENH1350EXT, ENS500-AC and ENS620EXT access points and restrict the management interface to trusted networks (management VLAN/VPN, WAN-side management disabled) until a fixed firmware is released, since the vendor has not yet published one and affected builds run through 20241118. Use the public PoC to hunt for signs of exploitation, such as unexpected diagnostic ping activity or unexplained configuration changes, and monitor for a vendor advisory or updated firmware.

Affected
EnGenius ENH1350EXT firmwareAll firmware up to 20241118; no fixed version identified in the available data
EnGenius ENS500-AC firmwareAll firmware up to 20241118; no fixed version identified in the available data
EnGenius ENS620EXT firmwareAll firmware up to 20241118; no fixed version identified in the available data
Estimated exposure
large~10,000-100,000 installed devices across the three models, with only a small fraction exposing the admin interface to the internet (order-of-magnitude estimate) — No public install-base counts or internet-exposure scan data exist for these legacy EnGenius outdoor access points, so the estimate is based on typical multi-year installed bases for mid-tier outdoor Wi-Fi models deployed in WISP,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_ping leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
engeniustech
Products
enh1350ext firmware, ens620ext firmware, ens500-ac firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.