Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown
CVE-2023-4452
Disclosure Date: November 01, 2023 (last updated November 10, 2023)
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.
0
Attacker Value
Unknown
CVE-2020-28144
Disclosure Date: February 03, 2021 (last updated February 22, 2025)
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
0
Attacker Value
Unknown
CVE-2019-10963
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.
0
Attacker Value
Unknown
CVE-2019-10969
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.
0
Attacker Value
Unknown
CVE-2018-16282
Disclosure Date: September 20, 2018 (last updated November 27, 2024)
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.
0
Attacker Value
Unknown
CVE-2017-14433
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetwork0= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2017-12127
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.
0
Attacker Value
Unknown
CVE-2017-12120
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation, resulting in a root shell. An attacker can inject OS commands into the ip= parm in the "/goform/net_WebPingGetValue" URI to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2017-14432
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the openvpnServer0_tmp= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2017-12126
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forgery. An attacker can create malicious HTML to trigger this vulnerability.
0