cbcvebase.
CVE-2016-8717
published 2018-04-02

CVE-2016-8717: An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.33%
81.5th percentile
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.

Affected

2 ranges
VendorProductVersion rangeFixed in
moxaawk-3131a_firmware
talosmoxa

Detection & IOCsextracted from sources · hover to see the quote

otherUsername: 94jo3dkru4 / Password: moxaiwroot
snort
Snort Rule SID 40758
  • Monitor SSH and Telnet login attempts using the hard-coded username '94jo3dkru4' against Moxa AWK-3131A devices; any successful or attempted authentication with this credential is a strong indicator of exploitation.
  • Deploy Snort rule SID 40758 to detect exploitation attempts of this hard-coded credential vulnerability on network traffic.
  • ·The hard-coded root account cannot be disabled or removed through normal device management; patching to the fixed firmware is the only permanent remediation.
  • ·If patching is not immediately possible, disable remotely-accessible services (SSH and Telnet) to reduce attack surface.
  • ·Snort rules for this vulnerability are subject to change as new information emerges; review Defense Centers or Snort.org for the latest rule versions.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.