An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to command injection via shell metacharacters.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-2773 An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to command injection via shell metacharacters.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T07:46:46.385Z

Reserved: 2018-05-03T00:00:00

Link: CVE-2018-10702

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-07T20:29:00.763

Modified: 2024-11-21T03:41:53.233

Link: CVE-2018-10702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.