PT-2020-1752 · Moxa · Moxa Awk-3131A
Published
2020-02-25
·
Updated
2022-06-13
·
CVE-2019-5141
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa AWK-3131A firmware version 1.13
Description
A command injection vulnerability exists in the iw webs functionality, allowing an attacker to gain remote control over the device. This can be achieved by sending specially crafted commands, utilizing the
iw serverip parameter, which can cause user input to be reflected in a subsequent iw system call. An attacker can exploit this vulnerability while authenticated as a low-privilege user.Recommendations
For Moxa AWK-3131A firmware version 1.13, consider disabling the
iw webs functionality until a patch is available to prevent exploitation of the command injection vulnerability. Restrict access to the iw serverip parameter to minimize the risk of remote control over the device. Avoid using the iw serverip parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Awk-3131A