engeniustech records
17 published records for vendor engeniustech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')9
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-284 Improper Access Control1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2025-34035Proof of concept | EnGenius EnShare IoT Gigabit Cloud Service Command Injectionengeniustech · esr300 firmware · CWE-78 | Critical10.0 | — | 12.5% | Jun 23, 2025 |
42Plan | CVE-2024-45242No exploit | EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping oCWE-78 | High7.8 | — | 35.4% | Oct 24, 2024 |
40Plan | CVE-2019-11353No exploit | The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute uengeniustech · ews660ap firmware · CWE-78 | Critical9.8 | — | 3.1% | May 9, 2019 |
39Monitor | CVE-2024-36061No exploit | EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection.engeniustech · ews356-fit firmware · CWE-78 | Critical9.8 | — | 1.1% | Nov 11, 2024 |
35Monitor | CVE-2024-36060No exploit | EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test paramCWE-78 | High8.8 | — | 1.4% | Oct 30, 2024 |
32Monitor | CVE-2024-31976No exploit | EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity paraengeniustech · ews356-fir firmware · CWE-78 | High8.0 | — | 1.0% | Nov 27, 2024 |
29Monitor | CVE-2024-11652No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT sn_https command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 30.2% | Nov 24, 2024 |
29Monitor | CVE-2024-11653No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 29.1% | Nov 25, 2024 |
29Monitor | CVE-2024-11658No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT ajax_getChannelList command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 29.1% | Nov 25, 2024 |
29Monitor | CVE-2024-11659No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_iperf command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 29.1% | Nov 25, 2024 |
29Monitor | CVE-2024-11657No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_nslookup command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 29.1% | Nov 25, 2024 |
29Monitor | CVE-2024-11654No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute6 command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 29.1% | Nov 25, 2024 |
29Monitor | CVE-2024-11655No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_pinginterface command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 28.8% | Nov 25, 2024 |
29Monitor | CVE-2024-11656No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_ping6 command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 28.8% | Nov 25, 2024 |
28Monitor | CVE-2024-11651No exploit | EnGenius ENH1350EXT/ENS500-AC/ENS620EXT wifi_schedule command injectionengeniustech · enh1350ext firmware · CWE-74 | Medium5.1 | — | 27.4% | Nov 24, 2024 |
26Monitor | CVE-2025-28371No exploit | EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function.engeniustech · enh500 firmware · CWE-284 | Medium6.5 | — | 0.5% | May 19, 2025 |
19Monitor | CVE-2024-31975No exploit | EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters.engeniustech · ews356-fit firmware · CWE-79 | Medium4.8 | — | 0.4% | Oct 30, 2024 |
- CVE-2025-3403544Plan
EnGenius EnShare IoT Gigabit Cloud Service Command Injection
CriticalCVSS 10.0Proof of conceptEPSS 13%engeniustech · esr300 firmwareJun 23, 2025
- CVE-2024-4524242Plan
EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping o
HighCVSS 7.8No exploitEPSS 35%Oct 24, 2024
- CVE-2019-1135340Plan
The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute u
CriticalCVSS 9.8No exploitEPSS 3%engeniustech · ews660ap firmwareMay 9, 2019
- CVE-2024-3606139Monitor
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection.
CriticalCVSS 9.8No exploitEPSS 1%engeniustech · ews356-fit firmwareNov 11, 2024
- CVE-2024-3606035Monitor
EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test param
HighCVSS 8.8No exploitEPSS 1%Oct 30, 2024
- CVE-2024-3197632Monitor
EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity para
HighCVSS 8.0No exploitEPSS 1%engeniustech · ews356-fir firmwareNov 27, 2024
- CVE-2024-1165229Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT sn_https command injection
MediumCVSS 5.1No exploitEPSS 30%engeniustech · enh1350ext firmwareNov 24, 2024
- CVE-2024-1165329Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute command injection
MediumCVSS 5.1No exploitEPSS 29%engeniustech · enh1350ext firmwareNov 25, 2024
- CVE-2024-1165829Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT ajax_getChannelList command injection
MediumCVSS 5.1No exploitEPSS 29%engeniustech · enh1350ext firmwareNov 25, 2024
- CVE-2024-1165929Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_iperf command injection
MediumCVSS 5.1No exploitEPSS 29%engeniustech · enh1350ext firmwareNov 25, 2024
- CVE-2024-1165729Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_nslookup command injection
MediumCVSS 5.1No exploitEPSS 29%engeniustech · enh1350ext firmwareNov 25, 2024
- CVE-2024-1165429Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute6 command injection
MediumCVSS 5.1No exploitEPSS 29%engeniustech · enh1350ext firmwareNov 25, 2024
- CVE-2024-1165529Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_pinginterface command injection
MediumCVSS 5.1No exploitEPSS 29%engeniustech · enh1350ext firmwareNov 25, 2024
- CVE-2024-1165629Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_ping6 command injection
MediumCVSS 5.1No exploitEPSS 29%engeniustech · enh1350ext firmwareNov 25, 2024
- CVE-2024-1165128Monitor
EnGenius ENH1350EXT/ENS500-AC/ENS620EXT wifi_schedule command injection
MediumCVSS 5.1No exploitEPSS 27%engeniustech · enh1350ext firmwareNov 24, 2024
- CVE-2025-2837126Monitor
EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function.
MediumCVSS 6.5No exploitEPSS 0%engeniustech · enh500 firmwareMay 19, 2025
- CVE-2024-3197519Monitor
EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters.
MediumCVSS 4.8No exploitEPSS 0%engeniustech · ews356-fit firmwareOct 30, 2024