Moxa Edr-G903 Firmware vulnerabilities

9 known vulnerabilities affecting moxa/edr-g903_firmware.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-4452HIGHCVSS 7.5fixed in 5.7.212023-11-01
CVE-2023-4452 [MEDIUM] CWE-120 CVE-2023-4452: A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vuln A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.
nvd
CVE-2020-28144CRITICALCVSS 9.8≤ 5.52021-02-03
CVE-2020-28144 [CRITICAL] CWE-119 CVE-2020-28144: Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series F Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
nvd
CVE-2020-14511CRITICALCVSS 9.8≤ 5.42020-07-15
CVE-2020-14511 [CRITICAL] CWE-121 CVE-2020-14511: Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).
nvd
CVE-2016-0876HIGHCVSS 7.5fixed in 3.4.122016-05-31
CVE-2016-0876 [HIGH] CWE-312 CVE-2016-0876: Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passw Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
nvd
CVE-2016-0879HIGHCVSS 7.5fixed in 3.4.122016-05-31
CVE-2016-0879 [HIGH] CWE-532 CVE-2016-0879: Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log file Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
nvd
CVE-2016-0878HIGHCVSS 7.5fixed in 3.4.122016-05-31
CVE-2016-0878 [HIGH] CVE-2016-0878: Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of servic Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.
nvd
CVE-2016-0877HIGHCVSS 7.5fixed in 3.4.122016-05-31
CVE-2016-0877 [HIGH] CWE-772 CVE-2016-0877: Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (memory consumption) by executing the ping function.
nvd
CVE-2016-0875HIGHCVSS 7.5fixed in 3.4.122016-05-31
CVE-2016-0875 [HIGH] CWE-532 CVE-2016-0875: Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and l Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
nvd
CVE-2012-4712MEDIUMCVSS 5.0fixed in 2.112013-02-15
CVE-2012-4712 [MEDIUM] CWE-798 CVE-2012-4712: Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.
nvd