VendorsEngeniustechews356-fit_firmwareany version
Vulnerabilities

Engeniustech ews356-fit Firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-36061
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.
Published 2024-11-11 · Analyzed
9.8EPSS 0.011
CVE-2024-31975
EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button.
Published 2024-10-30 · Analyzed
4.8EPSS 0.004