MOXA TN-4900是中国摩莎(MOXA)公司的一系列工业防火墙路由器。 MOXA TN-4900 v1.2.4 版本之前存在安全漏洞,该漏洞源于密钥删除功能中的输入验证不足,这可能允许恶意用户删除任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Moxa | TN-5900 Series | 1.0 ~ 3.3 | - |
|
| Moxa | TN-4900 Series | 1.0 ~ 1.2.4 | - |
|
| Moxa | EDR-G902 Series | 1.0 ~ 5.7.17 | - |
|
| Moxa | EDR-G903 Series | 1.0 ~ 5.7.15 | - |
|
| Moxa | EDR-G9010 Series | 1.0 ~ 2.1 | - |
|
| Moxa | NAT-102 Series | 1.0 ~ 1.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-34213 | 8.8 HIGH | Second Order Command-injection Vulnerability in the Key-generation Function |
| CVE-2023-33239 | 8.8 HIGH | Second Order Command-injection Vulnerability in the Key-generation Function |
| CVE-2023-33237 | 8.8 HIGH | Authentication Bypass Without Administrator Privilege |
| CVE-2023-34217 | 8.1 HIGH | Second Order Command-injection Vulnerability in the Certificate-delete Function |
| CVE-2023-34215 | 7.2 HIGH | Second Order Command-injection Vulnerability in the Certificate-generation Function |
| CVE-2023-34214 | 7.2 HIGH | Second Order Command-injection Vulnerability in the Certificate-generation Function |
| CVE-2023-33238 | 7.2 HIGH | Command-injection Vulnerability in Certificate Management |
No comments yet