CVE-2016-8721 CRITICAL

CVE-2016-8721

Vendor Moxa
Product Moxa AWK-3131A WAP
Published April 20, 2017
Last update August 6, 2024

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete compromise of the vulnerable device. An attacker can exploit this vulnerability remotely.

Key dates

02Disclosure timeline

April 20, 2017 CVE published
August 6, 2024 Record updated