PT-2022-5680 · Moxa · Moxa Edr-G903+4

Published

2022-11-29

·

Updated

2022-11-29

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa EDR-810 versions (affected versions not specified) Moxa EDR-G902 versions (affected versions not specified) Moxa EDR-G903 versions (affected versions not specified) Moxa TN-4900 versions (affected versions not specified) Moxa TN-5916 versions (affected versions not specified)
Description The issue is related to errors in processing input data in the command interpreter of the web service microprogram for Moxa router devices. Exploitation of the issue may allow a remote attacker to execute arbitrary code by sending a specially crafted HTTP/HTTPS request.
Recommendations For Moxa EDR-810, at the moment, there is no information about a newer version that contains a fix for this issue. For Moxa EDR-G902, at the moment, there is no information about a newer version that contains a fix for this issue. For Moxa EDR-G903, at the moment, there is no information about a newer version that contains a fix for this issue. For Moxa TN-4900, at the moment, there is no information about a newer version that contains a fix for this issue. For Moxa TN-5916, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-07075

Affected Products

Moxa Edr-810
Moxa Edr-G902
Moxa Edr-G903
Moxa Tn-4900
Moxa Tn-5916