MOXA TN-4900是中国摩莎(MOXA)公司的一系列工业防火墙路由器。 MOXA TN-4900 v1.2.4 版本之前存在安全漏洞,该漏洞源于证书管理功能中的输入验证不足,这可能允许恶意用户在受影响的设备上执行远程代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Moxa | TN-5900 Series | 1.0 ~ 3.3 | - |
|
| Moxa | TN-4900 Series | 1.0 ~ 1.2.4 | - |
|
| Moxa | EDR-810 Series | 1.0 ~ 5.12.27 | - |
|
| Moxa | EDR-G902 Series | 1.0 ~ 5.7.17 | - |
|
| Moxa | EDR-G903 Series | 1.0 ~ 5.7.15 | - |
|
| Moxa | EDR-G9010 Series | 1.0 ~ 2.1 | - |
|
| Moxa | NAT-102 Series | 1.0 ~ 1.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-34213 | 8.8 HIGH | Second Order Command-injection Vulnerability in the Key-generation Function |
| CVE-2023-33239 | 8.8 HIGH | Second Order Command-injection Vulnerability in the Key-generation Function |
| CVE-2023-33237 | 8.8 HIGH | Authentication Bypass Without Administrator Privilege |
| CVE-2023-34217 | 8.1 HIGH | Second Order Command-injection Vulnerability in the Certificate-delete Function |
| CVE-2023-34216 | 8.1 HIGH | Second Order Command-injection Vulnerability in the Key-delete Function |
| CVE-2023-34215 | 7.2 HIGH | Second Order Command-injection Vulnerability in the Certificate-generation Function |
| CVE-2023-34214 | 7.2 HIGH | Second Order Command-injection Vulnerability in the Certificate-generation Function |
No comments yet