Multiple product vulnerabilities were identified in Moxa’s OnCell G3150A/G3470A Series and WDR-3124A Series Cellular Gateways/Router. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Command Injection for Authentication (CWE-77), CVE-2021-37752 | An attacker located remotely can execute arbitrary commands on the device via a web interface. |
| 2 | Authentication Bypass and Unencrypted Credentials (CWE-303, CWE-256), CVE-2021-37753, CVE-2021-37755 |
An attacker located remotely can bypass authentication mechanisms. |
| 3 | Improper Restriction That Causes Buffer Overflow (CWE-119), CVE-2021-37757 |
An attacker located remotely can crash the service of the devices. |
| 4 | Reveals Sensitive Information to an Unauthorized Actor (CWE-204), CVE-2021-37751 | An attacker located remotely can obtain sensitive information. |
| 5 | Improper Restriction of Excessive Authentication Attempts (CWE-307), CVE-2021-37754 |
An attacker located remotely can use brute force to obtain credentials. |
| 6 | Improper Verification of Firmware (CWE-347), CVE-2021-37758 |
An attacker can create malicious firmware for the device. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/oncell-g3150a-g3470-wdr-3124a-cellular-gateways-router-vulnerabilities