Moxa Awk-3121 Firmware vulnerabilities

14 known vulnerabilities affecting moxa/awk-3121_firmware.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2018-10698CRITICALCVSS 9.8v1.142019-06-07
CVE-2018-10698 [CRITICAL] CWE-311 CVE-2018-10698: An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET serv An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect to the TELNET daemon using the default credentials if they have not b
nvd
CVE-2018-10691HIGHCVSS 7.5v1.142019-06-07
CVE-2018-10691 [HIGH] CWE-284 CVE-2018-10691: An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can down An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.
nvd
CVE-2018-10693HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10693 [HIGH] CWE-119 CVE-2018-10693: An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an adm An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to a buffer overflow. By crafting a packet
nvd
CVE-2018-10694HIGHCVSS 8.1v1.142019-06-07
CVE-2018-10694 [HIGH] CWE-311 CVE-2018-10694: An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that i An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wireless connection to set up the device can allow an attacker to sniff the traffic passing between the user's computer and the device. This can allow an att
nvd
CVE-2018-10697HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10697 [HIGH] CWE-78 CVE-2018-10697: An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to this injection. By craftin
nvd
CVE-2018-10690HIGHCVSS 8.1v1.142019-06-07
CVE-2018-10690 [HIGH] CWE-311 CVE-2018-10690: An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thu An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allows an attacker to sniff the traffic easily and allows an attacker to compromise sensitive data such as credentials.
nvd
CVE-2018-10701HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10701 [HIGH] CWE-119 CVE-2018-10701: An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to buffer overflow. By crafting a packet that contains
nvd
CVE-2018-10703HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10703 [HIGH] CWE-119 CVE-2018-10703: An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_serverip" is susceptible to buffer overflow. By crafting a packet that contains
nvd
CVE-2018-10699HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10699 [HIGH] CWE-78 CVE-2018-10699: An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload fu An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_privatePass" is susceptible to th
nvd
CVE-2018-10695HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10695 [HIGH] CWE-119 CVE-2018-10695: An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an ad An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. However, the same functionality allows an attacker to execute commands on the device. The POST parameters "to1,to2,to3,to4" are all susceptible to buffer over
nvd
CVE-2018-10702HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10702 [HIGH] CWE-78 CVE-2018-10702: An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to command injection via shell metacharacters.
nvd
CVE-2018-10696HIGHCVSS 8.8v1.142019-06-07
CVE-2018-10696 [HIGH] CWE-352 CVE-2018-10696: An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters an
nvd
CVE-2018-10700MEDIUMCVSS 6.1v1.192019-06-07
CVE-2018-10700 [MEDIUM] CWE-79 CVE-2018-10700: An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administ An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter "iw_board_deviceName" is susceptible to this injection.
nvd
CVE-2018-10692MEDIUMCVSS 6.1v1.142019-06-07
CVE-2018-10692 [MEDIUM] CWE-79 CVE-2018-10692: An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not hav An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to steal the cookie very easily.
nvd