Moxa Secure Router Improper Ownership Management Vulnerability Allowing Access to Hashed Administrative Passwords

Vulnerability

A vulnerability has been identified in Moxa's Secure Router, related to improper ownership management. This issue allows a low-privileged authenticated user to access a configuration file that contains the hashed password of the administrative account. Exploitation of this vulnerability could lead to the unauthorized retrieval of sensitive information. However, this issue can only be exploited if the configuration file has been exported. The vulnerability does not affect the integrity or availability of the Secure Router, nor does it impact the confidentiality, integrity, or availability of any subsequent systems.

Impact

Successful exploitation allows access to a configuration file containing the hashed password of the administrative account, potentially leading to unauthorized access or privilege escalation.

Remediation

Users can update to firmware version 3.24 or later. For OnCell G4302-LTE4 Series and OnCell G4308-LTE4 Series, please contact Moxa Technical Support for the security patch (v3.24.1).

Added: Apr 27, 2026, 4:22 AM
Updated: Apr 27, 2026, 4:22 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
3.1
remediation
7.7
relevance
6.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.