ZeroHour

CVE-2024-36061

CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.

Vendors
engeniustech
Products
ews356-fit firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.