CVE-2019-5141: OS Command Injection
An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iwserverip parameter can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this command injection vulnerability?
The vulnerability ID is CVE-2019-5141.
What is the severity of CVE-2019-5141?
The severity of CVE-2019-5141 is high with a severity value of 8.8.
What is the affected software of CVE-2019-5141?
The affected software is Moxa AWK-3131A firmware version 1.13.
How does this vulnerability work?
This vulnerability allows an attacker to execute arbitrary commands on the affected device by manipulating the iw_serverip parameter.
Is there a fix available for CVE-2019-5141?
Yes, upgrading to a fixed version of the Moxa AWK-3131A firmware is recommended to mitigate this vulnerability.