logo

Industrial networking manufacturer Moxa reports ‘critical’ router bugs

ID: 22076a42-3b89-5df0-83f5-953879250d32

STIX ID: report--22076a42-3b89-5df0-83f5-953879250d32

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2025-01-06

Date Updated: 2026-04-21

Author: djohnson

...
...

Moxa disclosed two high-severity firmware vulnerabilities—CVE-2024-9138 (hardcoded credentials enabling privilege escalation to root) and CVE-2024-9140 (input-bypass leading to OS command injection exploitable remotely without authentication). Combined CVSS scores are 8.6 and 9.8; patches have been released for many but not all affected devices, and Moxa advises isolating vulnerable devices, restricting SSH, and monitoring for exploitation while some customers must contact support for updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.