EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.
https://github.com/actuator/cve/blob/main/Engenius/CVE-2024-36061