CVE-2020-28144: Buffer Overflow
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28144?
CVE-2020-28144 is a vulnerability that affects certain Moxa Inc products running EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower.
What is the severity of CVE-2020-28144?
CVE-2020-28144 has a severity rating of 9.8 (critical).
How can CVE-2020-28144 be exploited?
CVE-2020-28144 can be exploited by sending crafted requests to the affected device, allowing remote arbitrary code execution.
Which Moxa Inc products are affected by CVE-2020-28144?
Moxa EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower are affected by CVE-2020-28144.
How can I fix CVE-2020-28144?
To fix CVE-2020-28144, update the firmware of the affected Moxa Inc products to a version higher than the vulnerable versions listed (5.5 for EDR-G903 and EDR-G902, 5.6 for EDR-810).