CVE-2024-9140: OS Command Injection

Published Jan 3, 2025
·
Updated

Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s security and functionality.

Affected Software

3 affected components
MOXA cellular routers
MOXA secure routers
MOXA network security appliances

Remediation

Information

Moxa has developed appropriate solutions to address vulnerability. The solutions for the affected products are listed below. * EDR-8010 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-8010-series#resources  or later * EDR-G9004 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g9004-series#resources  or later * EDR-G9010 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g9010-series#resources  or later * EDF-G1002-BP Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/network-security-appliance/edf-g1002-bp-series#resources  or later * NAT-102 Series: An official patch or firmware update is not currently available for this product. Please refer to the Mitigations section below for recommended measures to address the vulnerability. * OnCell G4302-LTE4 Series: Please contact Moxa Technical Support https://www.moxa.com/support/support/technical-support  for the security patch * TN-4900 Series: Please contact Moxa Technical Support https://www.moxa.com/support/support/technical-support  for the security patch

Event History

Jan 3, 2025
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Jan 6, 2025
News Published
via BleepingComputer·05:15 PM
News Published
via BleepingComputer·05:17 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-9140?

CVE-2024-9140 is classified as a critical vulnerability due to its potential for OS command injection.

2

How do I fix CVE-2024-9140?

To mitigate CVE-2024-9140, ensure that your Moxa cellular routers, secure routers, and network security appliances are updated with the latest security patches provided by Moxa.

3

What types of devices are affected by CVE-2024-9140?

CVE-2024-9140 affects Moxa's cellular routers, secure routers, and network security appliances.

4

What potential impacts does CVE-2024-9140 pose?

CVE-2024-9140 may allow attackers to execute arbitrary code on affected devices, compromising their functionality and security.

5

Is there a way to identify if my device is vulnerable to CVE-2024-9140?

You can check if your Moxa devices are vulnerable to CVE-2024-9140 by reviewing their firmware version against the latest security advisories from Moxa.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203