CVE-2024-31975: Engeniustech EWS356-Fit Firmware
Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.
EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button.
Affected products
- Engeniustech EWS356-Fit Firmware: up to and including 1.1.30
Published 2024-10-30. Last modified 2026-06-17.