Записи engeniustech
17 опубликованных записей вендора engeniustech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')9
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-284 Improper Access Control1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2025-34035Proof of concept | EnGenius EnShare IoT Gigabit Cloud Service Command Injectionengeniustech · esr300 firmware · CWE-78 | Критическая10,0 | — | 12,5 % | 23 июн. 2025 г. |
42В плане | CVE-2024-45242Эксплойта нет | EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping oCWE-78 | Высокая7,8 | — | 35,4 % | 24 окт. 2024 г. |
40В плане | CVE-2019-11353Эксплойта нет | The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute uengeniustech · ews660ap firmware · CWE-78 | Критическая9,8 | — | 3,1 % | 9 мая 2019 г. |
39Наблюдать | CVE-2024-36061Эксплойта нет | EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection.engeniustech · ews356-fit firmware · CWE-78 | Критическая9,8 | — | 1,1 % | 11 нояб. 2024 г. |
35Наблюдать | CVE-2024-36060Эксплойта нет | EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test paramCWE-78 | Высокая8,8 | — | 1,4 % | 30 окт. 2024 г. |
32Наблюдать | CVE-2024-31976Эксплойта нет | EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity paraengeniustech · ews356-fir firmware · CWE-78 | Высокая8,0 | — | 1,0 % | 27 нояб. 2024 г. |
29Наблюдать | CVE-2024-11652Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT sn_https command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 30,2 % | 24 нояб. 2024 г. |
29Наблюдать | CVE-2024-11653Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 29,1 % | 25 нояб. 2024 г. |
29Наблюдать | CVE-2024-11658Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT ajax_getChannelList command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 29,1 % | 25 нояб. 2024 г. |
29Наблюдать | CVE-2024-11659Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_iperf command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 29,1 % | 25 нояб. 2024 г. |
29Наблюдать | CVE-2024-11657Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_nslookup command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 29,1 % | 25 нояб. 2024 г. |
29Наблюдать | CVE-2024-11654Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute6 command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 29,1 % | 25 нояб. 2024 г. |
29Наблюдать | CVE-2024-11655Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_pinginterface command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 28,8 % | 25 нояб. 2024 г. |
29Наблюдать | CVE-2024-11656Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_ping6 command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 28,8 % | 25 нояб. 2024 г. |
28Наблюдать | CVE-2024-11651Эксплойта нет | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT wifi_schedule command injectionengeniustech · enh1350ext firmware · CWE-74 | Средняя5,1 | — | 27,4 % | 24 нояб. 2024 г. |
26Наблюдать | CVE-2025-28371Эксплойта нет | EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function.engeniustech · enh500 firmware · CWE-284 | Средняя6,5 | — | 0,5 % | 19 мая 2025 г. |
19Наблюдать | CVE-2024-31975Эксплойта нет | EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters.engeniustech · ews356-fit firmware · CWE-79 | Средняя4,8 | — | 0,4 % | 30 окт. 2024 г. |
- CVE-2025-3403544В плане
EnGenius EnShare IoT Gigabit Cloud Service Command Injection
КритическаяCVSS 10,0Proof of conceptEPSS 13 %engeniustech · esr300 firmware23 июн. 2025 г.
- CVE-2024-4524242В плане
EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping o
ВысокаяCVSS 7,8Эксплойта нетEPSS 35 %24 окт. 2024 г.
- CVE-2019-1135340В плане
The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute u
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %engeniustech · ews660ap firmware9 мая 2019 г.
- CVE-2024-3606139Наблюдать
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %engeniustech · ews356-fit firmware11 нояб. 2024 г.
- CVE-2024-3606035Наблюдать
EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test param
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %30 окт. 2024 г.
- CVE-2024-3197632Наблюдать
EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity para
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %engeniustech · ews356-fir firmware27 нояб. 2024 г.
- CVE-2024-1165229Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT sn_https command injection
СредняяCVSS 5,1Эксплойта нетEPSS 30 %engeniustech · enh1350ext firmware24 нояб. 2024 г.
- CVE-2024-1165329Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute command injection
СредняяCVSS 5,1Эксплойта нетEPSS 29 %engeniustech · enh1350ext firmware25 нояб. 2024 г.
- CVE-2024-1165829Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT ajax_getChannelList command injection
СредняяCVSS 5,1Эксплойта нетEPSS 29 %engeniustech · enh1350ext firmware25 нояб. 2024 г.
- CVE-2024-1165929Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_iperf command injection
СредняяCVSS 5,1Эксплойта нетEPSS 29 %engeniustech · enh1350ext firmware25 нояб. 2024 г.
- CVE-2024-1165729Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_nslookup command injection
СредняяCVSS 5,1Эксплойта нетEPSS 29 %engeniustech · enh1350ext firmware25 нояб. 2024 г.
- CVE-2024-1165429Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute6 command injection
СредняяCVSS 5,1Эксплойта нетEPSS 29 %engeniustech · enh1350ext firmware25 нояб. 2024 г.
- CVE-2024-1165529Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_pinginterface command injection
СредняяCVSS 5,1Эксплойта нетEPSS 29 %engeniustech · enh1350ext firmware25 нояб. 2024 г.
- CVE-2024-1165629Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_ping6 command injection
СредняяCVSS 5,1Эксплойта нетEPSS 29 %engeniustech · enh1350ext firmware25 нояб. 2024 г.
- CVE-2024-1165128Наблюдать
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT wifi_schedule command injection
СредняяCVSS 5,1Эксплойта нетEPSS 27 %engeniustech · enh1350ext firmware24 нояб. 2024 г.
- CVE-2025-2837126Наблюдать
EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %engeniustech · enh500 firmware19 мая 2025 г.
- CVE-2024-3197519Наблюдать
EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters.
СредняяCVSS 4,8Эксплойта нетEPSS 0 %engeniustech · ews356-fit firmware30 окт. 2024 г.