CVE-2019-5162

HIGH

Moxa AWK-3131A <1.13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

References (1)

Core 1
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0955

Scores

CVSS v3 8.8
EPSS 0.0052
EPSS Percentile 67.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (1)
moxa/awk-3131a_firmware 1.13
Published Feb 25, 2020
Tracked Since Feb 18, 2026