PT-2019-8766 · Moxa · Moxa Awk-3121
Samuel Huntley
·
Published
2019-06-07
·
Updated
2020-08-24
·
CVE-2018-10699
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moxa AWK-3121 version 1.14
Description
An issue was discovered in the Moxa AWK-3121 device, specifically in its certfile upload functionality, which allows an administrator to upload a certificate file for connecting to the wireless network. However, this functionality also enables an attacker to execute commands on the device. The
iw privatePass parameter in the POST request is susceptible to command injection. By crafting a packet containing shell metacharacters, an attacker can execute the attack.Recommendations
For Moxa AWK-3121 version 1.14, consider disabling the certfile upload functionality until a patch is available to prevent command injection attacks. Restrict access to the
iw privatePass parameter in the POST request to minimize the risk of exploitation.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Awk-3121