6.1
CVSSv3

CVE-2021-39278

Published: 07/09/2021 Updated: 09/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moxa wac-2004_firmware 1.7

moxa wac-1001_firmware 2.1

moxa wac-1001-t_firmware 2.1

moxa oncell_g3470a-lte-eu_firmware 1.7

moxa oncell_g3470a-lte-eu-t_firmware 1.7

moxa tap-323-eu-ct-t_firmware 1.3

moxa tap-323-us-ct-t_firmware 1.3

moxa tap-323-jp-ct-t_firmware 1.3

moxa wdr-3124a-eu_firmware 2.3

moxa wdr-3124a-eu-t_firmware 2.3

moxa wdr-3124a-us_firmware 2.3

moxa wdr-3124a-us-t_firmware 2.3

Exploits

Many Moxa devices suffer from command injection, cross site scripting, and outdated software vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SEC Consult SA-20210901-0 :: Multiple vulnerabilities in MOXA devices <!--X-Subject-Header-End--> <!--X-Head-of-Messag ...