CVE-2025-34035 is an OS command injection vulnerability in EnGenius EnShare Cloud Service version 1.4.11 and earlier. A CGI handler inadequately sanitizes input supplied through its path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. These commands execute with root privileges, resulting in full system compromise. The Shadowserver Foundation observed exploitation evidence on December 5, 2024. The vulnerability was subsequently exploited during the second stage of the ClingSTUN backdoor campaign.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability exploited in the ClingSTUN campaign to compromise Internet-facing routers and IoT devices, establishing persistent backdoor access and remotely controlled proxy nodes. The content does not specify its technical mechanism or individually affected products.
An EnGenius cloud service vulnerability targeted during the second stage of the ClingSTUN campaign. The content does not specify its technical mechanism.
An EnGenius cloud service vulnerability targeted during ClingSTUN's second campaign stage as the operators expanded beyond their initial router exploit. The content does not specify its technical mechanism.
A vulnerability in EnGenius's IoT cloud service exploited during the second observed period of the ClingSTUN campaign. The content does not describe the flaw's technical mechanism.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.