Vulnerability Details CVE-2024-36061
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-36061
-
cpe:2.3:h:engeniustech:ews356-fit:-
-
cpe:2.3:o:engeniustech:ews356-fit_firmware:*