logo

Vulnerable Moxa devices expose industrial networks to attacks

ID: 7e2f254c-7b5d-5974-9476-2d91461dd7ca

STIX ID: report--7e2f254c-7b5d-5974-9476-2d91461dd7ca

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-01-06

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Executive summary: Moxa disclosed two high-severity vulnerabilities affecting multiple cellular routers, secure routers, and network security appliances—CVE-2024-9138 (hard-coded credentials leading to root escalation) and CVE-2024-9140 (remote OS command injection allowing arbitrary code execution). The advisory identifies impacted models and firmware, provides firmware updates or vendor remediation guidance for many models, notes some devices currently lack patches, and recommends limiting network exposure and using firewalls/IDS/IPS while applying updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.