CVE-2019-11353

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
09/05/2019
Last modified:
24/08/2020

Description

The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters. This vulnerability is fixed in a later firmware version.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:engeniustech:ews660ap_firmware:2.0.284:*:*:*:*:*:*:*
cpe:2.3:h:engeniustech:ews660ap:-:*:*:*:*:*:*:*