CVE-2021-39278: XSS
Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39278?
CVE-2021-39278 has been rated as a medium severity vulnerability.
How do I fix CVE-2021-39278?
To fix CVE-2021-39278, users should upgrade their devices to the latest patched firmware versions provided by Moxa.
Which devices are affected by CVE-2021-39278?
CVE-2021-39278 affects several models including Moxa WAC-2004 1.7, WAC-1001 2.1, and OnCell G3470A-LTE-EU 1.7.
What type of vulnerability is CVE-2021-39278?
CVE-2021-39278 is a reflected Cross-Site Scripting (XSS) vulnerability.
Can CVE-2021-39278 be exploited remotely?
Yes, CVE-2021-39278 can be exploited remotely through the Config Import menu on the affected devices.