8.8
CVSSv3

CVE-2021-39279

Published: 07/09/2021 Updated: 09/09/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moxa wac-2004_firmware 1.7

moxa wac-1001_firmware 2.1

moxa wac-1001-t_firmware 2.1

moxa oncell_g3470a-lte-eu_firmware 1.7

moxa oncell_g3470a-lte-eu-t_firmware 1.7

moxa tap-323-eu-ct-t_firmware 1.3

moxa tap-323-us-ct-t_firmware 1.3

moxa tap-323-jp-ct-t_firmware 1.3

moxa wdr-3124a-eu_firmware 2.3

moxa wdr-3124a-eu-t_firmware 2.3

moxa wdr-3124a-us_firmware 2.3

moxa wdr-3124a-us-t_firmware 2.3

Exploits

Many Moxa devices suffer from command injection, cross site scripting, and outdated software vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SEC Consult SA-20210901-0 :: Multiple vulnerabilities in MOXA devices <!--X-Subject-Header-End--> <!--X-Head-of-Messag ...