PT-2018-15034 · Moxa · Nport W2X50A

Maksim Khazov

·

Published

2018-12-06

·

Updated

2019-01-30

·

CVE-2018-19659

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa NPort W2x50A products with firmware prior to 2.2 Build 18082311
Description An exploitable authenticated command-injection issue exists in the web server functionality. A specially crafted HTTP POST request to "/goform/net WebPingGetValue" can result in running OS commands as the root user.
Recommendations For Moxa NPort W2x50A products with firmware prior to 2.2 Build 18082311, update the firmware to version 2.2 Build 18082311 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/goform/net WebPingGetValue" endpoint to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19659

Affected Products

Nport W2X50A