Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Moxa Alerts Users to High-Severity Vulnerabilities in Cellular and Secure Routers

The Hacker News by The Hacker News
January 7, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jan 07, 2025Ravie LakshmananVulnerability / Network Security

Taiwan-based Moxa has warned of two security vulnerabilities impacting its cellular routers, secure routers, and network security appliances that could allow privilege escalation and command execution.

The list of vulnerabilities is as follows –

  • CVE-2024-9138 (CVSS 4.0 score: 8.6) – A hard-coded credentials vulnerability that could allow an authenticated user to escalate privileges and gain root-level access to the system, leading to system compromise, unauthorized modifications, data exposure, or service disruption
  • CVE-2024-9140 (CVSS 4.0 score: 9.3) – A vulnerability allows attackers to exploit special characters to bypass input restrictions, potentially leading to unauthorized command execution

The shortcomings, reported by security researcher Lars Haulin, affect the below products and firmware versions –

  • CVE-2024-9138 – EDR-810 Series (Firmware version 5.12.37 and earlier), EDR-8010 Series (Firmware version 3.13.1 and earlier), EDR-G902 Series (Firmware version 5.7.25 and earlier), EDR-G902 Series (Firmware version 5.7.25 and earlier), EDR-G9004 Series (Firmware version 3.13.1 and earlier), EDR-G9010 Series (Firmware version 3.13.1 and earlier), EDF-G1002-BP Series (Firmware version 3.13.1 and earlier), NAT-102 Series (Firmware version 1.0.5 and earlier), OnCell G4302-LTE4 Series (Firmware version 3.13 and earlier), and TN-4900 Series (Firmware version 3.13 and earlier)
  • CVE-2024-9140 – EDR-8010 Series (Firmware version 3.13.1 and earlier), EDR-G9004 Series (Firmware version 3.13.1 and earlier), EDR-G9010 Series (Firmware version 3.13.1 and earlier), EDF-G1002-BP Series (Firmware version 3.13.1 and earlier), NAT-102 Series (Firmware version 1.0.5 and earlier), OnCell G4302-LTE4 Series (Firmware version 3.13 and earlier), and TN-4900 Series (Firmware version 3.13 and earlier)
Cybersecurity

Patches have been made available for the following versions –

  • EDR-810 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-8010 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G902 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G903 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G9004 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G9010 Series (Upgrade to the firmware version 3.14 or later)
  • EDF-G1002-BP Series (Upgrade to the firmware version 3.14 or later)
  • NAT-102 Series (No official patch available)
  • OnCell G4302-LTE4 Series (Please contact Moxa Technical Support)
  • TN-4900 Series (Please contact Moxa Technical Support)

As mitigations, it’s recommended to ensure that devices are not exposed to the internet, limit SSH access to trusted IP addresses and networks using firewall rules or TCP wrappers, and implement measures to detect and prevent exploitation attempts.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
dLocal, Latin America’s answer to Stripe, wins UK license in global expansion push

dLocal, Latin America's answer to Stripe, wins UK license in global expansion push

Recommended.

The Humane Ai Pin Has Already Been Brought Back to Life

The Humane Ai Pin Has Already Been Brought Back to Life

March 1, 2025
Microsoft Q4 2025: CEO Nadella Claims Title Of AI Infrastructure Leader

Microsoft Q4 2025: CEO Nadella Claims Title Of AI Infrastructure Leader

July 31, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio