Metrics
Affected Vendors & Products
Tue, 26 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Engeniustech
Engeniustech enh1350ext Firmware Engeniustech ens500-ac Firmware Engeniustech ens620ext Firmware |
|
CPEs | cpe:2.3:o:engeniustech:enh1350ext_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:engeniustech:ens500-ac_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:engeniustech:ens620ext_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Engeniustech
Engeniustech enh1350ext Firmware Engeniustech ens500-ac Firmware Engeniustech ens620ext Firmware |
|
Metrics |
ssvc
|
Mon, 25 Nov 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT ajax_getChannelList command injection | |
Metrics |
cvssV4_0
|
cvssV3_0
|
Mon, 25 Nov 2024 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipulation of the argument countryCode leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-11-25T06:00:26.332Z
Updated: 2024-11-26T15:51:23.057Z
Reserved: 2024-11-24T15:14:10.255Z
Link: CVE-2024-11658
Updated: 2024-11-26T15:45:09.791Z
Status : Received
Published: 2024-11-25T06:15:06.593
Modified: 2024-11-25T06:15:06.593
Link: CVE-2024-11658
No data.