Vulnerabilities
15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-34035 | An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2024-12-05 UTC. NVD description · AI analysis pending | 10.0 | 13% | PoC ×3 |
| — | |
| CVE-2025-28371 | EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-31976 | EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter. EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter. NVD description · AI analysis pending | 8.0 | <1% |
| — | ||
| CVE-2024-11652 | Command injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT AP firmware EnGenius firmware for the ENH1350EXT, ENS500-AC and ENS620EXT outdoor access points, in versions up to and including the 20241118 (2024-11-18) build, contains a command-injection flaw (CWE-74/CWE-77) in the web management interface at /admin/sn_package/sn_https. A remote attacker who can reach that endpoint and holds high-privilege (administrative) credentials, per the CVSS 4.0 PR:H metric, can submit a manipulated https_enable parameter to inject operating-system commands on the device. Successful exploitation yields remote command execution, although the CVSS 4.0 impact metrics rate the resulting effect on confidentiality, integrity and availability as low. Any organization running these three EnGenius AP models with a reachable management interface is affected, with internet-exposed or remote-management-enabled deployments at greatest risk. A proof-of-concept exploit has already been published, EPSS assigns a 30.2% probability of exploitation within 30 days (98th percentile), the issue is not yet in CISA KEV, and the vendor was notified early but did not respond, so no fixed firmware is confirmed in the available data. Do: Because the vendor did not respond to the disclosure and no fixed firmware version appears in the available data, check EnGenius support channels for updated firmware for these three models and apply it when released. Until then, restrict access to the web management interface (/admin) to trusted networks or VPN rather than exposing it to the internet, and ensure strong administrator credentials are in use. Review device or reverse-proxy access logs for requests to /admin/sn_package/sn_https with unexpected https_enable values as indicators of probing or exploitation. | 5.1 | 30% | PoC |
| moderate~1,000-10,000 affected devices (total deployed units likely in the low tens of thousands; internet-exposed admin interfaces likely a smaller subset) | |
| CVE-2024-36061 | EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2024-31975 | EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2019-11353 | The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using di The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters. This vulnerability is fixed in a later firmware version. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — |