EnGenius EnShare Cloud Service是美国EnGenius公司的一款云端网络管理平台。 EnGenius EnShare Cloud Service 1.4.11及之前版本存在安全漏洞,该漏洞源于usbinteract.cgi脚本中path参数未清理导致OS命令注入攻击。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| EnGenius | EnShare IoT Gigabit Cloud Service | 0 ~ 1.4.11 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier.The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands.The injected commands are executed with root privileges, leading to full system compromise. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34035.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论