Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Moxa Alerts Users to High-Severity Vulnerabilities in Cellular and Secure Routers

The Hacker News by The Hacker News
January 7, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jan 07, 2025Ravie LakshmananVulnerability / Network Security

Taiwan-based Moxa has warned of two security vulnerabilities impacting its cellular routers, secure routers, and network security appliances that could allow privilege escalation and command execution.

The list of vulnerabilities is as follows –

  • CVE-2024-9138 (CVSS 4.0 score: 8.6) – A hard-coded credentials vulnerability that could allow an authenticated user to escalate privileges and gain root-level access to the system, leading to system compromise, unauthorized modifications, data exposure, or service disruption
  • CVE-2024-9140 (CVSS 4.0 score: 9.3) – A vulnerability allows attackers to exploit special characters to bypass input restrictions, potentially leading to unauthorized command execution

The shortcomings, reported by security researcher Lars Haulin, affect the below products and firmware versions –

  • CVE-2024-9138 – EDR-810 Series (Firmware version 5.12.37 and earlier), EDR-8010 Series (Firmware version 3.13.1 and earlier), EDR-G902 Series (Firmware version 5.7.25 and earlier), EDR-G902 Series (Firmware version 5.7.25 and earlier), EDR-G9004 Series (Firmware version 3.13.1 and earlier), EDR-G9010 Series (Firmware version 3.13.1 and earlier), EDF-G1002-BP Series (Firmware version 3.13.1 and earlier), NAT-102 Series (Firmware version 1.0.5 and earlier), OnCell G4302-LTE4 Series (Firmware version 3.13 and earlier), and TN-4900 Series (Firmware version 3.13 and earlier)
  • CVE-2024-9140 – EDR-8010 Series (Firmware version 3.13.1 and earlier), EDR-G9004 Series (Firmware version 3.13.1 and earlier), EDR-G9010 Series (Firmware version 3.13.1 and earlier), EDF-G1002-BP Series (Firmware version 3.13.1 and earlier), NAT-102 Series (Firmware version 1.0.5 and earlier), OnCell G4302-LTE4 Series (Firmware version 3.13 and earlier), and TN-4900 Series (Firmware version 3.13 and earlier)
Cybersecurity

Patches have been made available for the following versions –

  • EDR-810 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-8010 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G902 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G903 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G9004 Series (Upgrade to the firmware version 3.14 or later)
  • EDR-G9010 Series (Upgrade to the firmware version 3.14 or later)
  • EDF-G1002-BP Series (Upgrade to the firmware version 3.14 or later)
  • NAT-102 Series (No official patch available)
  • OnCell G4302-LTE4 Series (Please contact Moxa Technical Support)
  • TN-4900 Series (Please contact Moxa Technical Support)

As mitigations, it’s recommended to ensure that devices are not exposed to the internet, limit SSH access to trusted IP addresses and networks using firewall rules or TCP wrappers, and implement measures to detect and prevent exploitation attempts.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
dLocal, Latin America’s answer to Stripe, wins UK license in global expansion push

dLocal, Latin America's answer to Stripe, wins UK license in global expansion push

Recommended.

Former RingCentral CEO, HPE Top Exec Joins Pure Storage As New CFO

Former RingCentral CEO, HPE Top Exec Joins Pure Storage As New CFO

June 25, 2025
DXC Expands Consulting & Engineering Services Leadership to Scale AI-led Growth

DXC Expands Consulting & Engineering Services Leadership to Scale AI-led Growth

April 17, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio