← Back to browse · API

CVE-2025-34035

Severity
CRITICAL
CVSS
10.0
EPSS
0.12334
Risk score
44.32
CISA KEV
No
PoC
No
Published
2025-06-24
Modified
2026-04-07
First seen
2026-08-07
Aliases
EUVD-2025-18966, GHSA-XV32-FPQH-V67R
Products
EnGenius:EnShare IoT Gigabit Cloud Service 0 ≤1.4.11
Sources
euvd EUVD-2025-18966

Description

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2024-12-05 UTC.

References