CVE-2017-12123

HIGH

Moxa EDR-810 <V4.1 - Info Disclosure

Title source: llm

Description

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.

Scores

CVSS v3 8.8
EPSS 0.0017
EPSS Percentile 37.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status published

Affected Products (1)

moxa/edr-810_firmware

Timeline

Published May 14, 2018
Tracked Since Feb 18, 2026