Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 26 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Engeniustech
Engeniustech ews356-fit Engeniustech ews356-fit Firmware |
|
| CPEs | cpe:2.3:h:engeniustech:ews356-fit:-:*:*:*:*:*:*:* cpe:2.3:o:engeniustech:ews356-fit_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Engeniustech
Engeniustech ews356-fit Engeniustech ews356-fit Firmware |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 04 Nov 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EnGenius ESR580 devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button. | EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button. |
Thu, 31 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 30 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EnGenius ESR580 devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-04T16:46:37.618Z
Reserved: 2024-04-08T00:00:00.000Z
Link: CVE-2024-31975
Updated: 2024-10-31T15:55:10.180Z
Status : Analyzed
Published: 2024-10-30T18:15:06.967
Modified: 2026-01-26T18:01:15.307
Link: CVE-2024-31975
No data.
OpenCVE Enrichment
No data.