PT-2022-5680 · Moxa · Moxa Edr-G903+4
Published
2022-11-29
·
Updated
2022-11-29
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa EDR-810 versions (affected versions not specified)
Moxa EDR-G902 versions (affected versions not specified)
Moxa EDR-G903 versions (affected versions not specified)
Moxa TN-4900 versions (affected versions not specified)
Moxa TN-5916 versions (affected versions not specified)
Description
The issue is related to errors in processing input data in the command interpreter of the web service microprogram for Moxa router devices. Exploitation of the issue may allow a remote attacker to execute arbitrary code by sending a specially crafted HTTP/HTTPS request.
Recommendations
For Moxa EDR-810, at the moment, there is no information about a newer version that contains a fix for this issue.
For Moxa EDR-G902, at the moment, there is no information about a newer version that contains a fix for this issue.
For Moxa EDR-G903, at the moment, there is no information about a newer version that contains a fix for this issue.
For Moxa TN-4900, at the moment, there is no information about a newer version that contains a fix for this issue.
For Moxa TN-5916, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Edr-810
Moxa Edr-G902
Moxa Edr-G903
Moxa Tn-4900
Moxa Tn-5916