ZeroHour

CVE-2024-11659

PoC moderate

Command injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT firmware

CVSS 4.0
5.1 medium
EPSS
29%p98
Published
()
Modified
AI analysis

A command injection flaw (CWE-77/CWE-74) exists in the web management interface of EnGenius ENH1350EXT, ENS500-AC and ENS620EXT access point firmware, in the /admin/network/diag_iperf page, where the 'iperf' argument is not sanitized and allows injected operating-system commands to run on the device. The attack can be launched remotely, but the CVSS 4.0 vector (PR:H) indicates the attacker needs valid high-privilege (admin) credentials on the device; successful injection yields arbitrary command execution at device level, which could be used to tamper with the AP or pivot into the attached network. Firmware for all three models up to 2024-11-18 (20241118) is affected, and the vendor was reportedly contacted early but did not respond, so no fixed version is confirmed in this data. A public proof-of-concept is available, and EPSS assigns a 29.1% probability of exploitation within 30 days (98th percentile), though the flaw is not yet in CISA's KEV catalog.

What to do: Check EnGenius support channels for updated firmware for ENH1350EXT, ENS500-AC and ENS620EXT, since the vendor reportedly did not respond and no patched build is confirmed in the available data. Until a fix is available, avoid exposing these APs' management web interface to the internet, protect admin credentials (strong, unique passwords, management VLAN or VPN access only), and monitor the /admin/network/diag_iperf endpoint for suspicious requests. Treat the EPSS score (29.1% within 30 days) as a material exploitation risk and prioritize internet-reachable deployments.

Affected
EnGenius ENH1350EXT firmwareup to 20241118 (no fixed version confirmed; vendor did not respond to disclosure)
EnGenius ENS500-AC firmwareup to 20241118 (no fixed version confirmed; vendor did not respond to disclosure)
EnGenius ENS620EXT firmwareup to 20241118 (no fixed version confirmed; vendor did not respond to disclosure)
Estimated exposure
moderatelikely on the order of tens of thousands of deployed units worldwide, with only thousands (or fewer) having management interfaces reachable for remote attack — No public install or scan counts exist for these EnGenius business outdoor AP models, so this order-of-magnitude estimate reflects typical SMB/WISP outdoor access point deployment patterns, where units are older, deployed in small numbers…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipulation of the argument iperf leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
engeniustech
Products
enh1350ext firmware, ens620ext firmware, ens500-ac firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.