peter bassill · operator
$ cve CVE-2019-11353 JSON

CVE-2019-11353

9.8
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters. This vulnerability is fixed in a later firmware version.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.07% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2019-05-09
Last modified2026-06-17

Affected (2)

VendorProduct
engeniustechews660ap
engeniustechews660ap firmware

References

→ the Explorer  ·  watch your stack  ·  NVD