First published: Thu Aug 17 2023(Updated: )
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.
Credit: psirt@moxa.com psirt@moxa.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Tn-5900 Firmware | <=3.3 | |
Moxa TN-5900 | ||
All of | ||
Moxa Tn-5900 Firmware | <=3.3 | |
Moxa TN-5900 |
Moxa has developed appropriate solution to address the vulnerability. The solution for affected products is shown below. * TN-5900 Series: Please upgrade to firmware v3.4 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34213 is a command-injection vulnerability in TN-5900 Series firmware versions v3.3 and prior.
CVE-2023-34213 has a severity rating of 9.8 (critical).
CVE-2023-34213 is caused by insufficient input validation and improper authentication in the key-generation function of TN-5900 Series firmware, allowing potential remote code execution.
TN-5900 Series firmware versions v3.3 and prior are vulnerable to CVE-2023-34213.
To mitigate CVE-2023-34213, it is recommended to update the TN-5900 Series firmware to a version higher than v3.3.