Moxa EDR-810
cpe:2.3:h:moxa:edr-810:*:*:*:*:*:*:*, +6 more
- <= 5.12.39
A command injection vulnerability has been identified in multiple Moxa product series, including secure routers, cellular routers, and network security appliances. This vulnerability allows remote attackers with web administrator privileges to execute arbitrary system commands through the NTP settings via the device's web interface. Successful exploitation can cause the device to enter an infinite reboot loop, resulting in a total or partial loss of connectivity for downstream systems that rely on its network services.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device, potentially leading to an infinite reboot loop and disruption of network services for connected downstream systems.
Users are advised to upgrade to the latest firmware version available for their specific product series. For some series, the updated firmware can be obtained by contacting Moxa Technical Support.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.