CVE-2019-5138
9.9
CRITICAL · CVSS 3.1 · EPSS 5.2% (pctl 92)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 5.16% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-02-25 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| moxa | awk-3131a |
| moxa | awk-3131a firmware |
References
→ the Explorer · watch your stack · NVD