Multiple product vulnerabilities were identified in Moxa’s AWK-3131A/4131A/1131A/1137C Series Wireless AP/Bridge/Client. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Command Injection for Authentication (CWE-77), CVE-2021-37752 | An attacker located remotely can execute arbitrary commands on the device via a web interface. |
| 2 | Authentication Bypass and Unencrypted Credentials (CWE-303, CWE-256), CVE-2021-37753, CVE-2021-37755 |
An attacker located remotely can bypass authentication mechanisms. |
| 3 | Improper Restriction That Causes Buffer Overflow (CWE-119), CVE-2021-37757 |
An attacker located remotely can crash the service of the devices. |
| 4 | Reveals Sensitive Information to an Unauthorized Actor (CWE-204), CVE-2021-37751 | An attacker located remotely can obtain sensitive information. |
| 5 | Improper Restriction of Excessive Authentication Attempts (CWE-307), CVE-2021-37754 |
An attacker located remotely can use brute force to obtain credentials. |
| 6 | Cross-site scripting (XSS) (CWE-79), CVE-2021-37756 |
An attacker located remotely can insert HTML and JavaScript into the system via a web interface. |
| 7 | Improper Verification of Firmware (CWE-347), CVE-2021-37758 |
An attacker can create malicious firmware for the device. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/awk-3131a-4131a-1131a-1137c-wireless-ap-bridge-client-vulnerabilities