ZeroHour

CVE-2024-11656

PoC large

Command injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access points

CVSS 4.0
5.1 medium
EPSS
29%p98
Published
()
Modified
AI analysis

CVE-2024-11656 is a command injection flaw (CWE-77) in the web management interface of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT wireless access points, occurring in the IPv6 ping diagnostic handler at the /admin/network/diag_ping6 endpoint. It is triggered by manipulating the diag_ping6 argument passed to that endpoint, causing attacker-supplied commands to be executed on the device; the attack is remote, and the CVSS 4.0 vector (PR:H) indicates the attacker needs high-privilege, i.e. admin-level, access to the management interface. Successful exploitation allows arbitrary command execution on the AP, with the CVSS scoring the resulting system impact as low. Only these three EnGenius product lines running firmware up to and including the 20241118 build are affected. A public proof of concept exists, the EPSS score of 28.8% (98th percentile) signals meaningful near-term exploitation risk, the flaw is not yet in CISA's KEV, and the vendor was notified but did not respond, so no fixed firmware version is confirmed in the available data.

What to do: Restrict the devices' web management interface to trusted management networks or VPN access and avoid exposing it directly to the internet, and audit admin credentials, since the injection requires high-privilege access. Monitor the EnGenius support portal for updated firmware for the ENH1350EXT, ENS500-AC and ENS620EXT, as the vendor had not responded at disclosure and no fixed version is confirmed in the available data. Watch for suspicious requests to /admin/network/diag_ping6 as an indicator of probing or exploitation attempts.

Affected
EnGenius Technologies ENH1350EXT firmwareup to and including 20241118
EnGenius Technologies ENS500-AC firmwareup to and including 20241118
EnGenius Technologies ENS620EXT firmwareup to and including 20241118
Estimated exposure
large≈10,000–100,000 deployed units across the three AP models (estimate; the internet-exposed subset is likely smaller) — EnGenius is a niche enterprise/SMB Wi-Fi vendor and these are older outdoor access-point lines whose cumulative deployments are plausibly in the tens of thousands, with only a fraction having internet-exposed management interfaces; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the argument diag_ping6 leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
engeniustech
Products
enh1350ext firmware, ens620ext firmware, ens500-ac firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.