CVE-2021-39278
Moxa Command Injection / Cross Site Scripting / Vulnerable Software
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.
Determinados dispositivos MOXA permiten un ataque de tipo XSS reflejado por medio del menú Config Import. Esto afecta a WAC-2004 versión 1.7, WAC-1001 versión 2.1, WAC-1001-T versión 2.1, OnCell G3470A-LTE-EU versión 1.7, OnCell G3470A-LTE-EU-T versión 1.7, TAP-323-EU-CT-T versión 1.3, TAP-323-US-CT-T versión 1.3, TAP-323-JP-CT-T versión 1.3, WDR-3124A-EU versión 2.3, WDR-3124A-EU-T versión 2.3, WDR-3124A-US versión 2.3 y WDR-3124A-US-T versión 2.3
Many Moxa devices suffer from command injection, cross site scripting, and outdated software vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-18 CVE Reserved
- 2021-09-01 CVE Published
- 2024-05-23 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/164014 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Wac-2004 Firmware Search vendor "Moxa" for product "Wac-2004 Firmware" | 1.7 Search vendor "Moxa" for product "Wac-2004 Firmware" and version "1.7" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wac-2004 Search vendor "Moxa" for product "Wac-2004" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wac-1001 Firmware Search vendor "Moxa" for product "Wac-1001 Firmware" | 2.1 Search vendor "Moxa" for product "Wac-1001 Firmware" and version "2.1" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wac-1001 Search vendor "Moxa" for product "Wac-1001" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wac-1001-t Firmware Search vendor "Moxa" for product "Wac-1001-t Firmware" | 2.1 Search vendor "Moxa" for product "Wac-1001-t Firmware" and version "2.1" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wac-1001-t Search vendor "Moxa" for product "Wac-1001-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu Firmware Search vendor "Moxa" for product "Oncell G3470a-lte-eu Firmware" | 1.7 Search vendor "Moxa" for product "Oncell G3470a-lte-eu Firmware" and version "1.7" | - |
Affected
| in | Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu Search vendor "Moxa" for product "Oncell G3470a-lte-eu" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu-t Firmware Search vendor "Moxa" for product "Oncell G3470a-lte-eu-t Firmware" | 1.7 Search vendor "Moxa" for product "Oncell G3470a-lte-eu-t Firmware" and version "1.7" | - |
Affected
| in | Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu-t Search vendor "Moxa" for product "Oncell G3470a-lte-eu-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Tap-323-eu-ct-t Firmware Search vendor "Moxa" for product "Tap-323-eu-ct-t Firmware" | 1.3 Search vendor "Moxa" for product "Tap-323-eu-ct-t Firmware" and version "1.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Tap-323-eu-ct-t Search vendor "Moxa" for product "Tap-323-eu-ct-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Tap-323-us-ct-t Firmware Search vendor "Moxa" for product "Tap-323-us-ct-t Firmware" | 1.3 Search vendor "Moxa" for product "Tap-323-us-ct-t Firmware" and version "1.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Tap-323-us-ct-t Search vendor "Moxa" for product "Tap-323-us-ct-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Tap-323-jp-ct-t Firmware Search vendor "Moxa" for product "Tap-323-jp-ct-t Firmware" | 1.3 Search vendor "Moxa" for product "Tap-323-jp-ct-t Firmware" and version "1.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Tap-323-jp-ct-t Search vendor "Moxa" for product "Tap-323-jp-ct-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-eu Firmware Search vendor "Moxa" for product "Wdr-3124a-eu Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-eu Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-eu Search vendor "Moxa" for product "Wdr-3124a-eu" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-eu-t Firmware Search vendor "Moxa" for product "Wdr-3124a-eu-t Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-eu-t Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-eu-t Search vendor "Moxa" for product "Wdr-3124a-eu-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-us Firmware Search vendor "Moxa" for product "Wdr-3124a-us Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-us Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-us Search vendor "Moxa" for product "Wdr-3124a-us" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-us-t Firmware Search vendor "Moxa" for product "Wdr-3124a-us-t Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-us-t Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-us-t Search vendor "Moxa" for product "Wdr-3124a-us-t" | - | - |
Safe
|