8.8
CVSSv3

CVE-2018-19659

Published: 06/12/2018 Updated: 30/01/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware prior to 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/net_WebPingGetValue can result in running OS commands as the root user. This is similar to CVE-2017-12120.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moxa nport_w2x50a_firmware

Exploits

Moxa NPort W2x50A products with firmware version 21 Build_17112017 or lower are vulnerable to several authenticated OS command injection vulnerabilities ...

Mailing Lists

Moxa NPort W2x50A products with firmware version 21 Build_17112017 or lower are vulnerable to several authenticated OS Command Injection vulnerabilities: #1 Authenticated OS Command Injection in web server ping functionality Reserverd CVE ID: CVE-2018-19659 A specially crafted HTTP POST request to /goform/net_WebPingGetValue can result in runn ...