CVE-2024-9140
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 3, 2025
CWE ID 78
Summary
CVE-2024-9140 is a critical vulnerability affecting Moxa's cellular routers, secure routers, and network security appliances. The issue stems from insufficient command restrictions, enabling OS command injection. Attackers can exploit this vulnerability to execute arbitrary code, posing a significant risk to both the targeted system's security and functionality. This vulnerability could potentially allow unauthorized access, data theft, or system disruption. Moxa's users are urged to apply the forthcoming patches or updates to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.