PT-2021-7467 · Moxa · Awk-1131A+5
Published
2021-12-30
·
Updated
2021-12-30
·
CVE-2021-37756
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa AWK-3131A, AWK-4131A, AWK-1131A, and AWK-1137C (affected versions not specified)
Moxa TAP-323 (affected versions not specified)
Moxa TAP-213 (affected versions not specified)
Description
The issue is related to the web interface of Moxa's wireless access point firmware, where the structure of web pages is not properly protected. This could allow a remote attacker to perform cross-site scripting attacks.
Recommendations
For Moxa AWK-3131A, AWK-4131A, AWK-1131A, and AWK-1137C, consider restricting access to the web interface until a fix is available.
For Moxa TAP-323 and Moxa TAP-213, avoid using the web interface for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Awk-1131A
Awk-1137C
Awk-3131A
Awk-4131A
Tap-213
Tap-323