10.0
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2024-12-05 UTC.
Affected (52)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.0.28 |
| Running on/with | Platform Versions |
|---|---|
Engeniustech Esr300 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.0.29 |
| Running on/with | Platform Versions |
|---|---|
Engeniustech Esr350 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.0.50 |
| Running on/with | Platform Versions |
|---|---|
Engeniustech Esr600 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.0 |
| Running on/with | Platform Versions |
|---|---|
Engeniustech Esr900 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.0 |
| Running on/with | Platform Versions |
|---|---|
Engeniustech Esr1200 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.0 |
| Running on/with | Platform Versions |
|---|---|
Engeniustech Esr1750 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.0 |
| Running on/with | Platform Versions |
|---|---|
Engeniustech Epg5000 | All versions |
References (6)
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Source: disclosure@vulncheck.com
Third Party Advisory
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory
Timeline
No history available yet.