CVE-2018-10699: OS Command Injection
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iwprivatePass" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10699?
CVE-2018-10699 is classified as a critical vulnerability due to its potential for command execution on affected devices.
How do I fix CVE-2018-10699?
To fix CVE-2018-10699, it is recommended to upgrade the Moxa AWK-3121 firmware to a version that addresses this vulnerability.
What devices are affected by CVE-2018-10699?
CVE-2018-10699 affects Moxa AWK-3121 devices running firmware version 1.14.
What type of attacks can be executed due to CVE-2018-10699?
Attackers can exploit CVE-2018-10699 to execute arbitrary commands on the device through the certificate upload functionality.
Is there a known exploit for CVE-2018-10699?
Yes, details regarding the exploit for CVE-2018-10699 are discussed in various security reports and advisories.