ZeroHour

CVE-2024-11658

PoC niche

Command Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT APs

CVSS 4.0
5.1 medium
EPSS
29%p98
Published
()
Modified
AI analysis

Three EnGenius access point models (ENH1350EXT, ENS500-AC, ENS620EXT) contain a command injection flaw in the admin interface's /admin/network/ajax_getChannelList function, where the countryCode argument is not properly sanitized. An attacker with access to the device's management interface — the CVSS 4.0 vector (PR:H) indicates admin-level authentication is required — submits a crafted countryCode value, causing arbitrary OS command execution on the access point. Successful exploitation can allow the attacker to run commands on the device, alter its configuration, disrupt wireless service, or pivot into the network behind it; the CVSS 4.0 base score of 5.1 (medium) reflects low individual impact on confidentiality, integrity and availability. Any organization running ENH1350EXT, ENS500-AC or ENS620EXT firmware up to the 2024-11-18 builds is affected. A public proof of concept exists and the flaw carries an elevated 29.1% EPSS exploitation probability (98th percentile), but it is not yet in CISA KEV and no confirmed in-the-wild exploitation is known; the vendor was contacted but did not respond, so no fixed firmware has been confirmed.

What to do: Because the vendor did not respond to the disclosure, no fixed firmware version is confirmed — check EnGenius's support/download pages for updated firmware for ENH1350EXT, ENS500-AC and ENS620EXT and apply it if released. In the meantime, do not expose the devices' admin interface to the WAN (restrict it to a management VLAN or firewall it), use strong admin credentials, and consider validating or constraining the countryCode parameter if custom filtering is possible. Review the public proof of concept to confirm whether your devices parse input through ajax_getChannelList, and monitor devices for unexpected configuration changes or suspicious processes.

Affected
engeniustech enh1350ext firmwareup to and including 20241118 (builds through 2024-11-18)
engeniustech ens500-ac firmwareup to and including 20241118 (builds through 2024-11-18)
engeniustech ens620ext firmwareup to and including 20241118 (builds through 2024-11-18)
Estimated exposure
nichelikely on the order of tens of thousands of deployed units worldwide, with only a subset (thousands or fewer) exposing the admin interface to the internet — These are legacy outdoor/business-class WLAN access points sold primarily to SMBs and WISP operators rather than the consumer mass market, and remote exploitation additionally requires an internet-exposed management interface plus admin…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipulation of the argument countryCode leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
engeniustech
Products
enh1350ext firmware, ens620ext firmware, ens500-ac firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.