Skip to main content

Vendor archive

moxa CVEs

Beta · best-effort

289 CVEs tagged to vendor moxa63 Critical, 161 High, 60 Medium, 5 Low, 0 Unrated.

CVE-2017-14459

Published Apr 11, 2018

An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/cli…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7506

Published Apr 6, 2018

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encry…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8717

Published Apr 2, 2018

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocum…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-5455

Published Mar 5, 2018

A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows…

CVSS 9.8 · Critical

CVE-2018-5453

Published Mar 5, 2018

An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit…

CVSS 7.5 · High

CVE-2018-5449

Published Mar 5, 2018

A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application does not check for a NULL value, allowing fo…

CVSS 6.5 · Medium

CVE-2017-5170

Published Jan 18, 2018

An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrolled search path element (DLL Hijacking)…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12729

Published Jan 18, 2018

A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14030

Published Jan 12, 2018

An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13701

Published Nov 23, 2017

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Inde…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-13699

Published Nov 23, 2017

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13698

Published Nov 23, 2017

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract public and private keys from the firmware image available on the MOXA website and c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7917

Published May 29, 2017

A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and pre…

CVSS 8.8 · High

CVE-2017-7915

Published May 29, 2017

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Ve…

CVSS 9.8 · Critical

CVE-2017-7913

Published May 29, 2017

A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 an…

CVSS 9.8 · Critical

CVE-2016-8721

Published Apr 20, 2017

An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially craft…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7457

Published Apr 14, 2017

XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7456

Published Apr 14, 2017

Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 289 CVEsPage 9 of 12