CVE-2024-11654
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_traceroute6 leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published:Nov 25, 2024
Last Modified:Feb 12, 2025
EPS:Nov 25, 2024
EPSS Score:0.0165
CVSS Score:4.7
Affected Products
Vendor
Product
Action
Vendor
Engenius
Product
Enh1350ext
Engenius
Enh1350ext
Vendor
Engenius
Product
Ens500-ac
Engenius
Ens500-ac
Vendor
Engenius
Product
Ens620ext
Engenius
Ens620ext
Vendor
Engeniustech
Product
Enh1350ext
Engeniustech
Enh1350ext
Vendor
Engeniustech
Product
Enh1350ext Firmware
Engeniustech
Enh1350ext Firmware
Vendor
Engeniustech
Product
Ens500-ac
Engeniustech
Ens500-ac
Vendor
Engeniustech
Product
Ens500-ac Firmware
Engeniustech
Ens500-ac Firmware
Vendor
Engeniustech
Product
Ens620ext
Engeniustech
Ens620ext
Vendor
Engeniustech
Product
Ens620ext Firmware
Engeniustech
Ens620ext Firmware
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
