CVE-2024-9140

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 3, 2025
CWE ID 78

Summary

CVE-2024-9140 is a critical vulnerability affecting Moxa's cellular routers, secure routers, and network security appliances. The issue stems from insufficient command restrictions, enabling OS command injection. Attackers can exploit this vulnerability to execute arbitrary code, posing a significant risk to both the targeted system's security and functionality. This vulnerability could potentially allow unauthorized access, data theft, or system disruption. Moxa's users are urged to apply the forthcoming patches or updates to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share