CVE-2021-39279
Moxa Command Injection / Cross Site Scripting / Vulnerable Software
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.
Determinados dispositivos MOXA permiten una inyección de comandos autenticados por medio de /forms/web_importTFTP. Esto afecta a WAC-2004 versión 1.7, WAC-1001 versión 2.1, WAC-1001-T versión 2.1, OnCell G3470A-LTE-EU versión 1.7, OnCell G3470A-LTE-EU-T versión 1.7, TAP-323-EU-CT-T versión 1.3, TAP-323-US-CT-T versión 1.3, TAP-323-JP-CT-T versión 1.3, WDR-3124A-EU versión 2.3, WDR-3124A-EU-T versión 2.3, WDR-3124A-US versión 2.3 y WDR-3124A-US-T versión 2.3
Many Moxa devices suffer from command injection, cross site scripting, and outdated software vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-18 CVE Reserved
- 2021-09-01 CVE Published
- 2021-09-09 First Exploit
- 2024-08-04 CVE Updated
- 2024-09-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstormsecurity.com/files/164014 | 2021-09-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.moxa.com | 2021-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Wac-2004 Firmware Search vendor "Moxa" for product "Wac-2004 Firmware" | 1.7 Search vendor "Moxa" for product "Wac-2004 Firmware" and version "1.7" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wac-2004 Search vendor "Moxa" for product "Wac-2004" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wac-1001 Firmware Search vendor "Moxa" for product "Wac-1001 Firmware" | 2.1 Search vendor "Moxa" for product "Wac-1001 Firmware" and version "2.1" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wac-1001 Search vendor "Moxa" for product "Wac-1001" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wac-1001-t Firmware Search vendor "Moxa" for product "Wac-1001-t Firmware" | 2.1 Search vendor "Moxa" for product "Wac-1001-t Firmware" and version "2.1" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wac-1001-t Search vendor "Moxa" for product "Wac-1001-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu Firmware Search vendor "Moxa" for product "Oncell G3470a-lte-eu Firmware" | 1.7 Search vendor "Moxa" for product "Oncell G3470a-lte-eu Firmware" and version "1.7" | - |
Affected
| in | Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu Search vendor "Moxa" for product "Oncell G3470a-lte-eu" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu-t Firmware Search vendor "Moxa" for product "Oncell G3470a-lte-eu-t Firmware" | 1.7 Search vendor "Moxa" for product "Oncell G3470a-lte-eu-t Firmware" and version "1.7" | - |
Affected
| in | Moxa Search vendor "Moxa" | Oncell G3470a-lte-eu-t Search vendor "Moxa" for product "Oncell G3470a-lte-eu-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Tap-323-eu-ct-t Firmware Search vendor "Moxa" for product "Tap-323-eu-ct-t Firmware" | 1.3 Search vendor "Moxa" for product "Tap-323-eu-ct-t Firmware" and version "1.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Tap-323-eu-ct-t Search vendor "Moxa" for product "Tap-323-eu-ct-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Tap-323-us-ct-t Firmware Search vendor "Moxa" for product "Tap-323-us-ct-t Firmware" | 1.3 Search vendor "Moxa" for product "Tap-323-us-ct-t Firmware" and version "1.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Tap-323-us-ct-t Search vendor "Moxa" for product "Tap-323-us-ct-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Tap-323-jp-ct-t Firmware Search vendor "Moxa" for product "Tap-323-jp-ct-t Firmware" | 1.3 Search vendor "Moxa" for product "Tap-323-jp-ct-t Firmware" and version "1.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Tap-323-jp-ct-t Search vendor "Moxa" for product "Tap-323-jp-ct-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-eu Firmware Search vendor "Moxa" for product "Wdr-3124a-eu Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-eu Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-eu Search vendor "Moxa" for product "Wdr-3124a-eu" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-eu-t Firmware Search vendor "Moxa" for product "Wdr-3124a-eu-t Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-eu-t Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-eu-t Search vendor "Moxa" for product "Wdr-3124a-eu-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-us Firmware Search vendor "Moxa" for product "Wdr-3124a-us Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-us Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-us Search vendor "Moxa" for product "Wdr-3124a-us" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Wdr-3124a-us-t Firmware Search vendor "Moxa" for product "Wdr-3124a-us-t Firmware" | 2.3 Search vendor "Moxa" for product "Wdr-3124a-us-t Firmware" and version "2.3" | - |
Affected
| in | Moxa Search vendor "Moxa" | Wdr-3124a-us-t Search vendor "Moxa" for product "Wdr-3124a-us-t" | - | - |
Safe
|