CVE-2019-5142

HIGH

Moxa AWK-3131A <1.13 - Command Injection

Title source: llm
STIX 2.1

Description

An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.

References (1)

Core 1
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0931

Scores

CVSS v3 7.2
EPSS 0.0221
EPSS Percentile 84.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
moxa/awk-3131a_firmware 1.13
Published Feb 25, 2020
Tracked Since Feb 18, 2026