CVE-2024-11657
PoC moderateCommand Injection in EnGenius ENH1350EXT, ENS500-AC, ENS620EXT Firmware
CVE-2024-11657 is a command injection flaw in the EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access point firmware (all builds up to 20241118), triggered via the diag_nslookup argument passed to the /admin/network/diag_nslookup endpoint. The attack is launched remotely, and the CVSS 4.0 vector indicates it requires high privileges (i.e., valid admin-level access to the device's web interface), yielding limited-volume confidentiality, integrity and availability impact per the score. An attacker who is authenticated as an administrator (or who has obtained admin credentials) can inject and execute operating-system commands on the device. All users running affected firmware versions of these three EnGenius models are in scope. A proof-of-concept exploit has been published publicly, EPSS puts the 30-day exploitation probability at 29.1% (98th percentile), and the vendor was notified early but has not responded, so no confirmed fix is available yet.
What to do: Because the vendor has not responded, no fixed firmware version is confirmed — monitor EnGenius support channels for an updated release for these three models. Until a patch ships, restrict the device admin interface to trusted networks or VPN access and ensure strong, unique admin credentials, since the CVSS vector indicates admin privileges are required to exploit. Given the published PoC and elevated EPSS (29.1%), check device logs for unexpected requests to /admin/network/diag_nslookup.
| engeniustech ENH1350EXT firmware | up to 20241118 |
| engeniustech ENS500-AC firmware | up to 20241118 |
| engeniustech ENS620EXT firmware | up to 20241118 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the file /admin/network/diag_nslookup. The manipulation of the argument diag_nslookup leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.