CVE-2021-39279: OS Command Injection
Certain MOXA devices allow Authenticated Command Injection via /forms/webimportTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39279?
CVE-2021-39279 is classified as a medium severity vulnerability due to the potential for authenticated command injection.
How do I fix CVE-2021-39279?
To remediate CVE-2021-39279, you should update your Moxa devices to the latest firmware versions that close this vulnerability.
Which Moxa devices are affected by CVE-2021-39279?
CVE-2021-39279 affects multiple Moxa devices, including WAC-2004, WAC-1001, OnCell G3470A-LTE-EU, TAP-323 models, and WDR-3124A series.
What type of vulnerability is CVE-2021-39279?
CVE-2021-39279 is an authenticated command injection vulnerability that allows attackers to execute commands on affected Moxa devices.
Is CVE-2021-39279 exploitable remotely?
CVE-2021-39279 can be exploited by authenticated users, which means the attacker has to have valid credentials for the Moxa devices.