CVE-2024-11658
PoC nicheCommand Injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT APs
Three EnGenius access point models (ENH1350EXT, ENS500-AC, ENS620EXT) contain a command injection flaw in the admin interface's /admin/network/ajax_getChannelList function, where the countryCode argument is not properly sanitized. An attacker with access to the device's management interface — the CVSS 4.0 vector (PR:H) indicates admin-level authentication is required — submits a crafted countryCode value, causing arbitrary OS command execution on the access point. Successful exploitation can allow the attacker to run commands on the device, alter its configuration, disrupt wireless service, or pivot into the network behind it; the CVSS 4.0 base score of 5.1 (medium) reflects low individual impact on confidentiality, integrity and availability. Any organization running ENH1350EXT, ENS500-AC or ENS620EXT firmware up to the 2024-11-18 builds is affected. A public proof of concept exists and the flaw carries an elevated 29.1% EPSS exploitation probability (98th percentile), but it is not yet in CISA KEV and no confirmed in-the-wild exploitation is known; the vendor was contacted but did not respond, so no fixed firmware has been confirmed.
What to do: Because the vendor did not respond to the disclosure, no fixed firmware version is confirmed — check EnGenius's support/download pages for updated firmware for ENH1350EXT, ENS500-AC and ENS620EXT and apply it if released. In the meantime, do not expose the devices' admin interface to the WAN (restrict it to a management VLAN or firewall it), use strong admin credentials, and consider validating or constraining the countryCode parameter if custom filtering is possible. Review the public proof of concept to confirm whether your devices parse input through ajax_getChannelList, and monitor devices for unexpected configuration changes or suspicious processes.
| engeniustech enh1350ext firmware | up to and including 20241118 (builds through 2024-11-18) |
| engeniustech ens500-ac firmware | up to and including 20241118 (builds through 2024-11-18) |
| engeniustech ens620ext firmware | up to and including 20241118 (builds through 2024-11-18) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipulation of the argument countryCode leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.