Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. Any commands (including device reboot, configuration download or upload, or firmware upgrade) are accepted and executed by the device without authentication.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMoxa Oncell G3150 Hspa
HWMoxaall versionsMoxa Oncell G3150 Hspa Firmware
OSMoxa≤ 1.6Moxa Oncell G3150 Hspa T
HWMoxaall versionsMoxa Oncell G3150 Hspa T Firmware
OSMoxa≤ 1.6
Related vulnerabilities
Podatność Auth Bypass w Moxa OnCell G3100-HSPA — słaby parametr Cookie
Moxa OnCell G3100-HSPA: transmisja danych jawnym tekstem, ujawnienie hasła administratora
Uszkodzenie pamięci w interfejsie webowym Moxa OnCell G3100-HSPA
Moxa OnCell G3100-HSPA — pominięcie uwierzytelnienia przez brute force cookie
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 an...