Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Moxa Alerts Users to High-Severity Vulnerabilities in Cellular and Secure Routers

The Hacker News by The Hacker News
January 7, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jan 07, 2025Ravie LakshmananVulnerability / Network Security

Taiwan-based Moxa has warned of two security vulnerabilities impacting its cellular routers, secure routers, and network security appliances that could allow privilege escalation and command execution.

The list of vulnerabilities is as follows –

  • CVE-2024-9138 (CVSS 4.0 score: 8.6) – A hard-coded credentials vulnerability that could allow an authenticated user to escalate privileges and gain root-level access to the system, leading to system compromise, unauthorized modifications, data exposure, or service disruption
  • CVE-2024-9140 (CVSS 4.0 score: 9.3) – A vulnerability allows attackers to exploit special characters to bypass input restrictions, potentially leading to unauthorized command execution

The shortcomings, reported by security researcher Lars Haulin, affect the below products and firmware versions –

  • CVE-2024-9138 – EDR-810 Series (Firmware version 5.12.37 and earlier), EDR-8010 Series (Firmware version 3.13.1 and earlier), EDR-G902 Series (Firmware version 5.7.25 and earlier), EDR-G902 Series (Firmware version 5.7.25 and earlier), EDR-G9004 Series (Firmware version 3.13.1 and earlier), EDR-G9010 Series (Firmware version 3.13.1 and earlier), EDF-G1002-BP Series (Firmware version 3.13.1 and earlier), NAT-102 Series (Firmware version 1.0.5 and earlier), OnCell G4302-LTE4 Series (Firmware version 3.13 and earlier), and TN-4900 Series (Firmware version 3.13 and earlier)
  • CVE-2024-9140 – EDR-8010 Series (Firmware version 3.13.1 and earlier), EDR-G9004 Series (Firmware version 3.13.1 and earlier), EDR-G9010 Series (Firmware version 3.13.1 and earlier), EDF-G1002-BP Series (Firmware version 3.13.1 and earlier), NAT-102 Series (Firmware version 1.0.5 and earlier), OnCell G4302-LTE4 Series (Firmware version 3.13 and earlier), and TN-4900 Series (Firmware version 3.13 and earlier)
Cybersecurity

Patches have been made available for the following versions –

  • EDR-810 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-8010 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G902 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G903 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G9004 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G9010 Series (Upgrade to the firmware version 3.14 or later)
  • EDF-G1002-BP Series (Upgrade to the firmware version 3.14 or later)
  • NAT-102 Series (No official patch available)
  • OnCell G4302-LTE4 Series (Please contact Moxa Technical Support)
  • TN-4900 Series (Please contact Moxa Technical Support)

As mitigations, it’s recommended to ensure that devices are not exposed to the internet, limit SSH access to trusted IP addresses and networks using firewall rules or TCP wrappers, and implement measures to detect and prevent exploitation attempts.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
dLocal, Latin America’s answer to Stripe, wins UK license in global expansion push

dLocal, Latin America's answer to Stripe, wins UK license in global expansion push

Recommended.

Fractus étend son programme de licences aux points de vente (PDV) verticaux

Fractus étend son programme de licences aux points de vente (PDV) verticaux

November 27, 2025
Aryaka Brings On New Global Channel Chief Nick Alagna, Reveals ‘Significant’ Global SASE Investment, Expansion

Aryaka Brings On New Global Channel Chief Nick Alagna, Reveals ‘Significant’ Global SASE Investment, Expansion

March 4, 2025

Trending.

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

March 10, 2026
Huawei lanceert Next Generation FAN-oplossing

Huawei lanceert Next Generation FAN-oplossing

March 7, 2026
Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

February 26, 2026
Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio