nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-14459 CVE-2017-14459
CRITICAL
Moxa AWK-3131A 1.4 < 1.7 - 'Username' OS Command Injection
Record summary
CVE-2017-14459 has a selected CVSS score of 10.0 (critical); EIP currently links 1 catalogued exploit.
Description
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client versions 1.4 - 1.9. In addition, versions prior to 1.4 appear similarly vulnerable to injection, but not as easily exploitable (described below). Other models in the AWK product line may likewise be vulnerable but have not been tested. | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMoxa AWK-3131A 1.4 < 1.7 - 'Username' OS Command InjectionExploitDB exploitby TalosNot analyzed1 file
References
2talosintelligence.com
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0507