CVE-2023-33238

HIGH

TN-4900/TN-5900 <1.2.4/<3.3 - Command Injection

Title source: llm
STIX 2.1

Description

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate management function, which could potentially allow malicious users to execute remote code on affected devices.

Scores

CVSS v3 7.2
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78 CWE-77
Status published
Products (2)
moxa/tn-4900_firmware < 1.2.4
moxa/tn-5900_firmware < 3.3
Published Aug 17, 2023
Tracked Since Feb 18, 2026