PT-2019-8766 · Moxa · Moxa Awk-3121

Samuel Huntley

·

Published

2019-06-07

·

Updated

2020-08-24

·

CVE-2018-10699

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa AWK-3121 version 1.14
Description An issue was discovered in the Moxa AWK-3121 device, specifically in its certfile upload functionality, which allows an administrator to upload a certificate file for connecting to the wireless network. However, this functionality also enables an attacker to execute commands on the device. The iw privatePass parameter in the POST request is susceptible to command injection. By crafting a packet containing shell metacharacters, an attacker can execute the attack.
Recommendations For Moxa AWK-3121 version 1.14, consider disabling the certfile upload functionality until a patch is available to prevent command injection attacks. Restrict access to the iw privatePass parameter in the POST request to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10699

Affected Products

Moxa Awk-3121