← Back to browse · API

CVE-2019-5153

Severity
CRITICAL
CVSS
9.9
EPSS
0.0438
Risk score
41.13
CISA KEV
No
PoC
No
Published
2020-02-25
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-14758, GHSA-RX2C-347V-F3F4
Products
Moxa:Moxa Moxa AWK-3131A Firmware version 1.13
Sources
euvd EUVD-2019-14758

Description

An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

References