CVE-2024-36061

CRITICAL

EnGenius EWS356-FIT <1.1.30 - Command Injection

Title source: llm
STIX 2.1

Description

EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.

Scores

CVSS v3 9.8
EPSS 0.0106
EPSS Percentile 77.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
engeniustech/ews356-fit_firmware < 1.1.30
Published Nov 11, 2024
Tracked Since Feb 18, 2026