Description
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.
References (1)
Core 1
Core References
Exploit, Mitigation, Third Party Advisory x_refsource_misc
http://www.talosintelligence.com/reports/TALOS-2016-0230
Scores
CVSS v3
7.5
EPSS
0.0083
EPSS Percentile
52.4%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-640
Status
published
Products (2)
Moxa/AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client
1.1
moxa/awk-3131a_firmware
1.1
Published
Apr 12, 2017
Tracked Since
Feb 18, 2026