Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Very High

CVE-2020-14511

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).
Attacker Value
Unknown

CVE-2024-9138

Disclosure Date: January 03, 2025 (last updated January 05, 2025)
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.
0
Attacker Value
Unknown

CVE-2023-4452

Disclosure Date: November 01, 2023 (last updated November 10, 2023)
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.
Attacker Value
Unknown

CVE-2020-28144

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
Attacker Value
Unknown

CVE-2016-0876

Disclosure Date: May 31, 2016 (last updated November 25, 2024)
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
Attacker Value
Unknown

CVE-2016-0877

Disclosure Date: May 31, 2016 (last updated November 25, 2024)
Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (memory consumption) by executing the ping function.
Attacker Value
Unknown

CVE-2016-0879

Disclosure Date: May 31, 2016 (last updated November 25, 2024)
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
Attacker Value
Unknown

CVE-2016-0875

Disclosure Date: May 31, 2016 (last updated November 25, 2024)
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
Attacker Value
Unknown

CVE-2016-0878

Disclosure Date: May 31, 2016 (last updated November 25, 2024)
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.
Attacker Value
Unknown

CVE-2012-4694

Disclosure Date: February 15, 2013 (last updated October 05, 2023)
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
0