Home

Description

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.

PUBLISHED Reserved 2024-09-24 | Published 2025-01-03 | Updated 2025-01-03 | Assigner Moxa




HIGH: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-656: Reliance on Security Through Obscurity

Product status

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Default status
unaffected

1.0 (custom)
affected

Credits

Lars Haulin finder

References

www.moxa.com/...-cellular-routers,-secure-routers,-and-netwo vendor-advisory

cve.org (CVE-2024-9138)

nvd.nist.gov (CVE-2024-9138)

Download JSON