Record summary

CVE-2017-14459 has a selected CVSS score of 10.0 (critical); EIP currently links 1 catalogued exploit.

Description

An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListMoxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client versions 1.4 - 1.9. In addition, versions prior to 1.4 appear similarly vulnerable to injection, but not as easily exploitable (described below). Other models in the AWK product line may likewise be vulnerable but have not been tested.affected

Proofs of concept

1

Catalogued exploits

ExploitDBMoxa AWK-3131A 1.4 < 1.7 - 'Username' OS Command InjectionExploitDB exploitby TalosNot analyzed1 file
ExploitDB

PoC details

References

2