Back

HIGH

Moxa Service Missing Authentication for Critical Function

Published Oct 14, 2024

Description

The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.

Affected products

Remediation

Vendor solution

Please refer to the security advisories: * Missing Authentication and OS Command Injection Vulnerabilities in Cellular Routers, Secure Routers, and Network Security Appliances https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241154-missing-authentication-and-os-command-injection-vulnerabilities-in-routers-and-network-security-appliances

* CVE-2024-9137: Missing Authentication Vulnerability in Ethernet Switches https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241156-cve-2024-9137-missing-authentication-vulnerability-in-ethernet-switches

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Moxa
Published Oct 14, 2024
Updated Sep 19, 2025
Reserved Sep 24, 2024
CISA Vulnrichment
Updated Oct 14, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Moxa
Published Oct 14, 2024
Updated Sep 19, 2025
Exploited since n/a
EUVD-2024-50423