PT-2021-7467 · Moxa · Awk-1131A+5

Published

2021-12-30

·

Updated

2021-12-30

·

CVE-2021-37756

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa AWK-3131A, AWK-4131A, AWK-1131A, and AWK-1137C (affected versions not specified) Moxa TAP-323 (affected versions not specified) Moxa TAP-213 (affected versions not specified)
Description The issue is related to the web interface of Moxa's wireless access point firmware, where the structure of web pages is not properly protected. This could allow a remote attacker to perform cross-site scripting attacks.
Recommendations For Moxa AWK-3131A, AWK-4131A, AWK-1131A, and AWK-1137C, consider restricting access to the web interface until a fix is available. For Moxa TAP-323 and Moxa TAP-213, avoid using the web interface for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06591
CVE-2021-37756

Affected Products

Awk-1131A
Awk-1137C
Awk-3131A
Awk-4131A
Tap-213
Tap-323