CVE-2024-11656
PoC largeCommand injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access points
CVE-2024-11656 is a command injection flaw (CWE-77) in the web management interface of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT wireless access points, occurring in the IPv6 ping diagnostic handler at the /admin/network/diag_ping6 endpoint. It is triggered by manipulating the diag_ping6 argument passed to that endpoint, causing attacker-supplied commands to be executed on the device; the attack is remote, and the CVSS 4.0 vector (PR:H) indicates the attacker needs high-privilege, i.e. admin-level, access to the management interface. Successful exploitation allows arbitrary command execution on the AP, with the CVSS scoring the resulting system impact as low. Only these three EnGenius product lines running firmware up to and including the 20241118 build are affected. A public proof of concept exists, the EPSS score of 28.8% (98th percentile) signals meaningful near-term exploitation risk, the flaw is not yet in CISA's KEV, and the vendor was notified but did not respond, so no fixed firmware version is confirmed in the available data.
What to do: Restrict the devices' web management interface to trusted management networks or VPN access and avoid exposing it directly to the internet, and audit admin credentials, since the injection requires high-privilege access. Monitor the EnGenius support portal for updated firmware for the ENH1350EXT, ENS500-AC and ENS620EXT, as the vendor had not responded at disclosure and no fixed version is confirmed in the available data. Watch for suspicious requests to /admin/network/diag_ping6 as an indicator of probing or exploitation attempts.
| EnGenius Technologies ENH1350EXT firmware | up to and including 20241118 |
| EnGenius Technologies ENS500-AC firmware | up to and including 20241118 |
| EnGenius Technologies ENS620EXT firmware | up to and including 20241118 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the argument diag_ping6 leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.