Moxa
Moxa Awk-3131a Firmware: vulnerabilidades y CVE
Moxa Awk-3131a Firmware tiene 28 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-5165 | Alta (7.2) | 2.1% | — | 25 feb 2020 | An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote… |
| CVE-2019-5162 | Alta (8.8) | 2.6% | — | 25 feb 2020 | An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an… |
| CVE-2019-5153 | Alta (8.8) | 4.4% | — | 25 feb 2020 | An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an… |
| CVE-2019-5148 | Alta (7.5) | 2.5% | — | 25 feb 2020 | An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that… |
| CVE-2019-5143 | Alta (8.8) | 4.5% | — | 25 feb 2020 | An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time… |
| CVE-2019-5142 | Alta (7.2) | 6.6% | — | 25 feb 2020 | An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of… |
| CVE-2019-5141 | Alta (8.8) | 4.9% | — | 25 feb 2020 | An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause user input to be reflected in a… |
| CVE-2019-5140 | Alta (8.8) | 2.8% | — | 25 feb 2020 | An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a… |
| CVE-2019-5139 | Alta (7.1) | 0.32% | — | 25 feb 2020 | An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password,… |
| CVE-2019-5138 | Crítica (9.9) | 5.2% | — | 25 feb 2020 | An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox… |
| CVE-2019-5137 | Alta (7.5) | 2.3% | — | 25 feb 2020 | The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13. |
| CVE-2019-5136 | Alta (8.8) | 2.4% | — | 25 feb 2020 | An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted… |
| CVE-2017-14459 | Crítica (9.8) | 13% | — | 11 abr 2018 | An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7… |
| CVE-2016-8717 | Crítica (9.8) | 2.1% | — | 2 abr 2018 | An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with… |
| CVE-2016-8721 | Crítica (9.1) | 3.3% | — | 20 abr 2017 | An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS… |
| CVE-2016-8727 | Alta (7.5) | 1.7% | — | 13 abr 2017 | An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authentication can reveal sensitive… |
| CVE-2016-8726 | Alta (7.5) | 1.4% | — | 13 abr 2017 | An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with… |
| CVE-2016-8725 | Media (5.3) | 1.3% | — | 13 abr 2017 | An exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access point running firmware 1.1. Retrieving a specific URL without authentication can… |
| CVE-2016-8724 | Media (5.3) | 4.2% | — | 13 abr 2017 | An exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted TCP query will allow an attacker to retrieve… |
| CVE-2016-8723 | Alta (7.5) | 1.4% | — | 13 abr 2017 | An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation… |
| CVE-2016-8722 | Media (5.3) | 1.3% | — | 13 abr 2017 | An exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client. Retrieving a specific URL without… |
| CVE-2016-8720 | Media (4.3) | 1.4% | — | 13 abr 2017 | An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in… |
| CVE-2016-8712 | Alta (8.1) | 1.4% | — | 13 abr 2017 | An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes… |
| CVE-2016-8719 | Media (6.1) | 0.82% | — | 12 abr 2017 | An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multiple parameters, can… |
| CVE-2016-8718 | Alta (8.8) | 0.54% | — | 12 abr 2017 | An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making… |
| CVE-2016-8716 | Alta (7.5) | 0.83% | — | 12 abr 2017 | An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web… |
| CVE-2016-8363 | Crítica (10) | 2.4% | — | 13 feb 2017 | An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series,… |
| CVE-2016-8362 | Media (6.5) | 1.3% | — | 13 feb 2017 | An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series,… |