CVE-2024-11659
PoC moderateCommand injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT firmware
A command injection flaw (CWE-77/CWE-74) exists in the web management interface of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access point firmware, in the /admin/network/diag_iperf page, where the 'iperf' argument is not sanitized and allows injected operating-system commands to run on the device. The attack can be launched remotely, but the CVSS 4.0 vector (PR:H) indicates the attacker needs valid high-privilege (admin) credentials on the device; successful injection yields arbitrary command execution at device level, which could be used to tamper with the AP or pivot into the attached network. Firmware for all three models up to 2024-11-18 (20241118) is affected, and the vendor was reportedly contacted early but did not respond, so no fixed version is confirmed in this data. A public proof-of-concept is available, and EPSS assigns a 29.1% probability of exploitation within 30 days (98th percentile), though the flaw is not yet in CISA's KEV catalog.
What to do: Check EnGenius support channels for updated firmware for ENH1350EXT, ENS500-AC and ENS620EXT, since the vendor reportedly did not respond and no patched build is confirmed in the available data. Until a fix is available, avoid exposing these APs' management web interface to the internet, protect admin credentials (strong, unique passwords, management VLAN or VPN access only), and monitor the /admin/network/diag_iperf endpoint for suspicious requests. Treat the EPSS score (29.1% within 30 days) as a material exploitation risk and prioritize internet-reachable deployments.
| EnGenius ENH1350EXT firmware | up to 20241118 (no fixed version confirmed; vendor did not respond to disclosure) |
| EnGenius ENS500-AC firmware | up to 20241118 (no fixed version confirmed; vendor did not respond to disclosure) |
| EnGenius ENS620EXT firmware | up to 20241118 (no fixed version confirmed; vendor did not respond to disclosure) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipulation of the argument iperf leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- engeniustech
- Products
- enh1350ext firmware, ens620ext firmware, ens500-ac firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.