← Back to browse · API

CVE-2019-5138

Severity
CRITICAL
CVSS
9.9
EPSS
0.05155
Risk score
41.4
CISA KEV
No
PoC
No
Published
2020-02-25
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-14743, GHSA-RFR7-5WCC-V3X3
Products
Moxa:Moxa Moxa AWK-3131A Firmware version 1.13
Sources
euvd EUVD-2019-14743

Description

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

References