Rewterz
Rewterz Threat Alert – Molerats spear phishing campaign
October 3, 2019
Rewterz
Rewterz Threat Alert – Lazarus Injector – IOC’s
October 4, 2019

Rewterz Threat Advisory – Moxa EDR 810 Series Multiple Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2019-10969 

An authenticated attacker may abuse the ping feature to execute unauthorized commands on the router, which could allow an attacker to perform remote code execution.

CVE-2019-10963

An unauthenticated attacker may be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.

Impact

  • Improper Input Validation
  • Improper Access Control

Affected Vendors

Moxa

Affected Products

EDR-810 All versions 5.1 and prior

Remediation

Moxa recommends users upgrade to the latest firmware, v5.2 or later.