Impact
The vulnerability allows an attacker with high privileges and access to the firmware update interface to supply a specially crafted firmware image that bypasses cryptographic signature verification. This causes the device to install the attacker’s firmware, enabling execution of arbitrary code, loss of device integrity, and potential denial of service. The flaw stems from improper cryptographic verification (CWE‑347) and can persist across future updates because malicious firmware is treated as legitimate.
Affected Systems
Moxa MGate MB3170 Series and MGate MB3270 Series devices are affected. No specific firmware version is listed beyond the product series, which is identified in the CPE as version 1.0.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, but EPSS is not available and the vulnerability is not listed in CISA KEV. Successful exploitation requires an attacker to have high privileges and access to the firmware update interface, which may be local or remote depending on configuration. The risk is that an insider or compromised account could upload malicious firmware, leading to persistent code execution on the device.
OpenCVE Enrichment