CVE-2024-36061

EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:engeniustech:ews356-fit_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:engeniustech:ews356-fit:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-11 20:15

Updated : 2026-01-26 16:12


NVD link : CVE-2024-36061

Mitre link : CVE-2024-36061

CVE.ORG link : CVE-2024-36061


JSON object : View

Products Affected

engeniustech

  • ews356-fit_firmware
  • ews356-fit
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')