CVE-2024-9139

HIGH

Product <Version - Command Injection

Title source: llm
STIX 2.1

Description

The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.

Scores

CVSS v3 7.2
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (8)
Moxa/EDF-G1002-BP Series 1.0 - 3.12.1
Moxa/EDR-8010 Series 1.0 - 3.12.1
Moxa/EDR-810 Series 1.0 - 5.12.33
Moxa/EDR-G9004 Series 1.0 - 3.12.1
Moxa/EDR-G9010 Series 1.0 - 3.12.1
Moxa/NAT-102 Series 1.0 - 1.0.5
Moxa/OnCell G4302-LTE4 Series 1.0 - 3.9
Moxa/TN-4900 Series 1.0 - 3.6
Published Oct 14, 2024
Tracked Since Feb 18, 2026