CVE-2017-14459 EXPLOIT
10.0
CRITICAL · CVSS 3.0 · EPSS 12.6% (pctl 96)
Patch early
A public exploit exists.
Description
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.
Scoring
| CVSS | 10.0 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 12.64% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-04-11 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| moxa | awk-3131a |
| moxa | awk-3131a firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Moxa AWK-3131A 1.4 < 1.7 - 'Username' OS Command Injection | 2017-04-03 |
References
→ the Explorer · watch your stack · NVD