CVE Feed

    Dashboard / CVE / CVE-2024-31975

    CVE-2024-31975

    EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button.

    Published:Oct 30, 2024
    Last Modified:Jan 26, 2026
    EPS:Oct 30, 2024
    EPSS Score:0.00026
    CVSS Score:4.8

    Affected Products

    Vendor
    Engeniustech
    Product
    Ews356-fit
    Vendor
    Engeniustech
    Product
    Ews356-fit Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High