cbcvebase.
CVE-2024-9140
published 2025-01-03

CVE-2024-9140: Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS…

PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.78%
75.6th percentile
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s security and functionality.

Affected

7 ranges
VendorProductVersion rangeFixed in
moxaedf-g1002-bp_series1.0 – 3.13.1
moxaedr-8010_series1.0 – 3.13.1
moxaedr-g9004_series1.0 – 3.13.1
moxaedr-g9010_series1.0 – 3.13.1
moxanat-102_series1.0 – 1.0.5
moxaoncell_g4302-lte4_series1.0 – 3.13
moxatn-4900_series1.0 – 3.13

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-9140 is remotely exploitable via OS command injection due to improper input restrictions on affected Moxa devices; monitor for unexpected command execution originating from network-facing interfaces (SSH, web management) on affected Moxa EDR/EDF/NAT/OnCell/TN series devices
  • Deploy IDS/IPS rules to monitor and block exploitation attempts targeting affected Moxa devices on industrial networks
  • ·EDR-8010 Series firmware 3.13.1 and earlier is vulnerable to CVE-2024-9140; patched in firmware 3.14 (released December 31, 2024)
  • ·EDR-G9004 Series firmware 3.13.1 and earlier is vulnerable to CVE-2024-9140; patched in firmware 3.14
  • ·EDR-G9010 Series firmware 3.13.1 and earlier is vulnerable to CVE-2024-9140; patched in firmware 3.14
  • ·EDF-G1002-BP Series firmware 3.13.1 and earlier is vulnerable to CVE-2024-9140; patched in firmware 3.14
  • ·NAT-102 Series firmware 1.0.5 and earlier is vulnerable to CVE-2024-9140; no patch currently available — mitigations only
  • ·OnCell G4302-LTE4 Series firmware 3.13 and earlier is vulnerable to CVE-2024-9140; contact Moxa support for patch guidance
  • ·TN-4900 Series firmware 3.13 and earlier is vulnerable to CVE-2024-9140; contact Moxa support for patch guidance
  • ·MRC-1002 Series, TN-5900 Series, and OnCell 3120-LTE-1 Series are explicitly NOT vulnerable to CVE-2024-9140

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.