PT-2020-1752 · Moxa · Moxa Awk-3131A

Published

2020-02-25

·

Updated

2022-06-13

·

CVE-2019-5141

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa AWK-3131A firmware version 1.13
Description A command injection vulnerability exists in the iw webs functionality, allowing an attacker to gain remote control over the device. This can be achieved by sending specially crafted commands, utilizing the iw serverip parameter, which can cause user input to be reflected in a subsequent iw system call. An attacker can exploit this vulnerability while authenticated as a low-privilege user.
Recommendations For Moxa AWK-3131A firmware version 1.13, consider disabling the iw webs functionality until a patch is available to prevent exploitation of the command injection vulnerability. Restrict access to the iw serverip parameter to minimize the risk of remote control over the device. Avoid using the iw serverip parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00992
CVE-2019-5141

Affected Products

Moxa Awk-3131A