PT-2021-7480 · Moxa · Awk-1137C+6
Published
2021-12-30
·
Updated
2021-12-30
·
CVE-2021-37752
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa OnCell G3150A-LTE versions (affected versions not specified)
Moxa OnCell G3470A-LTE versions (affected versions not specified)
Moxa WDR-3124A versions (affected versions not specified)
Moxa AWK-3131A versions (affected versions not specified)
Moxa AWK-4131A versions (affected versions not specified)
Moxa AWK-1131A versions (affected versions not specified)
Moxa AWK-1137C versions (affected versions not specified)
Description
The issue is related to a lack of data sanitization on the management level in the web interface of certain Moxa industrial LTE modems and wireless access points. This could allow a remote attacker to execute arbitrary commands.
Recommendations
For Moxa OnCell G3150A-LTE, consider restricting access to the web interface until a fix is available.
For Moxa OnCell G3470A-LTE, restrict access to the web interface until a fix is available.
For Moxa WDR-3124A, restrict access to the web interface until a fix is available.
For Moxa AWK-3131A, restrict access to the web interface until a fix is available.
For Moxa AWK-4131A, restrict access to the web interface until a fix is available.
For Moxa AWK-1131A, restrict access to the web interface until a fix is available.
For Moxa AWK-1137C, restrict access to the web interface until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Awk-1131A
Awk-1137C
Awk-3131A
Awk-4131A
Oncell G3150A-Lte
Oncell G3470A-Lte
Wdr-3124A