Security Advisory
CVE-2024-36061
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.