Skip to main content

Vendor/product archive

moxa / awk-3131a_firmware CVEs

Beta · best-effort

28 CVEs tagged to moxa / awk-3131a_firmware5 Critical, 17 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2019-5162

Published Feb 25, 2020

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user nam…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5142

Published Feb 25, 2020

An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5141

Published Feb 25, 2020

An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5140

Published Feb 25, 2020

An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5139

Published Feb 25, 2020

An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an u…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5138

Published Feb 25, 2020

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic scri…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5136

Published Feb 25, 2020

An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14459

Published Apr 11, 2018

An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/cli…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8717

Published Apr 2, 2018

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocum…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-8721

Published Apr 20, 2017

An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially craft…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8727

Published Apr 13, 2017

An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8726

Published Apr 13, 2017

An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8725

Published Apr 13, 2017

An exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access point running firmware 1.1. Retrieving a spec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8724

Published Apr 13, 2017

An exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted TCP…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8723

Published Apr 13, 2017

An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8722

Published Apr 13, 2017

An exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client. R…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8720

Published Apr 13, 2017

An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafte…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8712

Published Apr 13, 2017

An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8719

Published Apr 12, 2017

An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially cra…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8718

Published Apr 12, 2017

An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially craft…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2