cbcvebase.

Moxa Awk-3131A Firmware vulnerabilities

28 known vulnerabilities affecting moxa/awk-3131a_firmware.

Total CVEs
28
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH17MEDIUM6

Vulnerabilities

Page 2 of 2
CVE-2016-8723P3HIGHCVSS 7.5v1.12017-04-13
CVE-2016-8723 [HIGH] CWE-476 CVE-2016-8723: An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131 An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.
nvd
CVE-2016-8724P4MEDIUMCVSS 5.3v1.12017-04-13
CVE-2016-8724 [MEDIUM] CWE-200 CVE-2016-8724: An exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa An exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted TCP query will allow an attacker to retrieve potentially sensitive information.
nvd
CVE-2019-5139P4HIGHCVSS 7.1v1.132020-02-25
CVE-2019-5139 [HIGH] CWE-798 CVE-2019-5139: An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.
nvd
CVE-2016-8362P4MEDIUMCVSS 6.5≤ 10-31-20162017-02-13
CVE-2016-8362 [MEDIUM] CWE-287 CVE-2016-8362: An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Seri An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. Any us
nvd
CVE-2016-8722P4MEDIUMCVSS 5.3v1.12017-04-13
CVE-2016-8722 [MEDIUM] CWE-200 CVE-2016-8722: An exploitable Information Disclosure vulnerability exists in the Web Application functionality of M An exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client. Retrieving a specific URL without authentication can reveal sensitive information to an attacker.
nvd
CVE-2016-8725P4MEDIUMCVSS 5.3v1.12017-04-13
CVE-2016-8725 [MEDIUM] CWE-200 CVE-2016-8725: An exploitable information disclosure vulnerability exists in the Web Application functionality of t An exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access point running firmware 1.1. Retrieving a specific URL without authentication can reveal sensitive information to an attacker.
nvd
CVE-2016-8719P4MEDIUMCVSS 6.1v1.12017-04-12
CVE-2016-8719 [MEDIUM] CWE-79 CVE-2016-8719: An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functional An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multiple parameters, can cause a malicious scripts to be executed by a victim.
nvd
CVE-2016-8720P4MEDIUMCVSS 4.3v1.12017-04-13
CVE-2016-8720 [MEDIUM] CWE-74 CVE-2016-8720: An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of th An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be copied in to Location header of the HTTP response.
nvd
Moxa Awk-3131A Firmware vulnerabilities | cvebase