CVE-2024-45242
moderateRoot OS Command Injection in EnGenius ENH1350EXT Wi-Fi Devices
EnGenius ENH1350EXT devices running firmware through 3.9.3.2_c1.9.51 are vulnerable to a blind OS command injection (CWE-78) in the Ping and Speed Test utilities, where shell metacharacters supplied to those functions are passed to the underlying shell. The practical attack path occurs during initial setup, when the device broadcasts an open, unsecured Wi-Fi network and its admin panel still uses the factory default admin/admin credentials, allowing an attacker within Wi-Fi range to join the network, log in, and submit a malicious Ping or Speed Test request. Successful exploitation lets the attacker run arbitrary OS commands with root-level privileges, giving full control of the access point. Any deployment of an ENH1350EXT is affected, with the greatest risk for devices left in the initial-setup state with unchanged admin/admin credentials, though the injection can also be triggered by anyone with access to the device's admin utilities. No exploitation has been confirmed — the issue is not in CISA KEV and no public proof-of-concept is known — but EPSS assigns a 35.4% probability of exploitation within 30 days (98th percentile), signaling elevated near-term risk.
What to do: Upgrade ENH1350EXT firmware to a release newer than 3.9.3.2_c1.9.51 once EnGenius publishes a fix (check the EnGenius support/download portal for the latest release). Until then, immediately change the default admin/admin credentials, complete initial setup without leaving the device broadcasting the open setup network, and restrict admin-panel exposure. Treat the Ping and Speed Test utilities as a root command-execution path and monitor devices for signs of compromise.
| EnGenius ENH1350EXT (A8J-ENH1350EXT) | all firmware through 3.9.3.2_c1.9.51 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with the default credentials of admin/admin. An unauthorized attacker in proximity to the Wi-Fi network can exploit this window of time to execute arbitrary OS commands with root-level permissions.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.