CVE-2024-36061

EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.
Configurations

No configuration.

History

12 Nov 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-78

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Los dispositivos EnGenius EWS356-FIT hasta la versión 1.1.30 permiten la inyección ciega de comandos del sistema operativo. Esto permite que un atacante ejecute comandos arbitrarios del sistema operativo a través de metacaracteres de shell en las utilidades Ping y Speed Test.

11 Nov 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-11 20:15

Updated : 2024-11-12 17:35


NVD link : CVE-2024-36061

Mitre link : CVE-2024-36061

CVE.ORG link : CVE-2024-36061


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')