peter bassill · operator
$ cve CVE-2019-10969 JSON

CVE-2019-10969 EXPLOIT

7.2
HIGH · CVSS 3.1 · EPSS 10.6% (pctl 96)

Patch early

A public exploit exists.

Description

Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS10.62% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2019-10-08
Last modified2026-06-17

Affected (2)

VendorProduct
moxaedr-810
moxaedr-810 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD