Industrial networking manufacturer Moxa reports ‘critical’ router bugs
ID: 22076a42-3b89-5df0-83f5-953879250d32
STIX ID: report--22076a42-3b89-5df0-83f5-953879250d32
Feed Name: CyberScoop
Moxa disclosed two high-severity firmware vulnerabilities—CVE-2024-9138 (hardcoded credentials enabling privilege escalation to root) and CVE-2024-9140 (input-bypass leading to OS command injection exploitable remotely without authentication). Combined CVSS scores are 8.6 and 9.8; patches have been released for many but not all affected devices, and Moxa advises isolating vulnerable devices, restricting SSH, and monitoring for exploitation while some customers must contact support for updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
