9

CVE-2021-39279

Exploit
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Wac-2004 Firmware Version 1.7
   Moxa ≫ Wac-2004 Version -
Moxa ≫ Wac-1001 Firmware Version 2.1
   Moxa ≫ Wac-1001 Version -
Moxa ≫ Wac-1001-t Firmware Version 2.1
   Moxa ≫ Wac-1001-t Version -
Moxa ≫ Oncell G3470a-lte-eu Firmware Version 1.7
   Moxa ≫ Oncell G3470a-lte-eu Version -
Moxa ≫ Oncell G3470a-lte-eu-t Firmware Version 1.7
   Moxa ≫ Oncell G3470a-lte-eu-t Version -
Moxa ≫ Tap-323-eu-ct-t Firmware Version 1.3
   Moxa ≫ Tap-323-eu-ct-t Version -
Moxa ≫ Tap-323-us-ct-t Firmware Version 1.3
   Moxa ≫ Tap-323-us-ct-t Version -
Moxa ≫ Tap-323-jp-ct-t Firmware Version 1.3
   Moxa ≫ Tap-323-jp-ct-t Version -
Moxa ≫ Wdr-3124a-eu Firmware Version 2.3
   Moxa ≫ Wdr-3124a-eu Version -
Moxa ≫ Wdr-3124a-eu-t Firmware Version 2.3
   Moxa ≫ Wdr-3124a-eu-t Version -
Moxa ≫ Wdr-3124a-us Firmware Version 2.3
   Moxa ≫ Wdr-3124a-us Version -
Moxa ≫ Wdr-3124a-us-t Firmware Version 2.3
   Moxa ≫ Wdr-3124a-us-t Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.61% 0.905
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.moxa.com
Vendor Advisory
https://packetstormsecurity.com/files/164014
Third Party Advisory
Exploit
VDB Entry