Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tim124058

#28142of 53,622
9Total CVSS
Vulnerabilities · 1
PT-2018-13461
9.0
2018-09-20
Moxa · Moxa Edr-810 · CVE-2018-16282
**Name of the Vulnerable Software and Affected Versions** Moxa EDR-810 version 4.2 build 18041013 **Description** A command injection issue in the web server functionality allows remote attackers to execute arbitrary OS commands with root privilege. This is achieved via the `caname` parameter to the "/xml/net WebCADELETEGetValue" API endpoint. **Recommendations** For Moxa EDR-810 version 4.2 build 18041013, avoid using the `caname` parameter in the "/xml/net WebCADELETEGetValue" API endpoint until the issue is resolved. Restrict access to this endpoint to minimize the risk of exploitation.