Unrated severityNVD Advisory· Published Jun 24, 2025· Updated Apr 7, 2026
EnGenius EnShare IoT Gigabit Cloud Service Command Injection
CVE-2025-34035
Description
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2024-12-05 UTC.
Affected products
2- Range: <=1.4.11
- EnGenius/EnShare IoT Gigabit Cloud Servicev5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- cxsecurity.com/issue/WLB-2017060050mitrethird-party-advisoryexploit
- packetstormsecurity.com/files/142792mitrethird-party-advisoryexploit
- vulncheck.com/advisories/engenius-enshare-iot-gigabit-cloud-servicemitrethird-party-advisory
- www.exploit-db.com/exploits/42114mitrethird-party-advisoryexploit
- www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5413.phpmitrethird-party-advisoryexploit
News mentions
0No linked articles in our index yet.