CVE Database
/

CVE-2024-9137

Back to search

CVE-2024-9137

Published: Oct 14, 2024

Modified: Sep 19, 2025

PUBLISHED

CVSS v3.1

9.4

CRITICAL

Description

The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.

VendorProductVersions

Moxa

EDR-8010 Series

affected
1.0 - <= 3.12.1

Moxa

EDR-G9004 Series

affected
1.0 - <= 3.12.1

Moxa

EDR-G9010 Series

affected
1.0 - <= 3.12.1

Moxa

EDF-G1002-BP Series

affected
1.0 - <= 3.12.1

Moxa

NAT-102 Series

affected
1.0 - <= 1.0.5

Moxa

OnCell G4302-LTE4 Series

affected
1.0 - <= 3.9

Moxa

TN-4900 Series

affected
1.0 - <= 3.6

Moxa

EDS-608 Series

affected
1.0 - <= 3.12

Moxa

EDS-611 Series

affected
1.0 - <= 3.12

Moxa

EDS-616 Series

affected
1.0 - <= 3.12

Moxa

EDS-619 Series

affected
1.0 - <= 3.12

Moxa

EDS-405A Series

affected
1.0 - <= 3.14
unaffected
3.14.4

Moxa

EDS-408A Series

affected
1.0 - <= 3.12
unaffected
3.14.6

Moxa

EDS-505A Series

affected
1.0 - <= 3.11

Moxa

EDS-508A Series

affected
1.0 - <= 3.11

Moxa

EDS-510A Series

affected
1.0 - <= 3.12

Moxa

EDS-516A Series

affected
1.0 - <= 3.11

Moxa

EDS-518A Series

affected
1.0 - <= 3.11

Moxa

EDS-G509 Series

affected
1.0 - <= 3.10

Moxa

EDS-P510 Series

affected
1.0 - <= 3.11

Moxa

EDS-P510A Series

affected
1.0 - <= 3.11

Moxa

EDS-510E Series

affected
1.0 - <= 5.5

Moxa

EDS-518E Series

affected
1.0 - <= 6.3

Moxa

EDS-528E Series

affected
1.0 - <= 6.3

Moxa

EDS-G508E Series

affected
1.0 - <= 6.4

Moxa

EDS-G512E Series

affected
1.0 - <= 6.4

Moxa

EDS-G516E Series

affected
1.0 - <= 6.4

Moxa

EDS-P506E Series

affected
1.0 - <= 5.8

Moxa

ICS-G7526A Series

affected
1.0 - <= 5.10

Moxa

ICS-G7528A Series

affected
1.0 - <= 5.10

Moxa

ICS-G7748A Series

affected
1.0 - <= 5.9

Moxa

ICS-G7750A Series

affected
1.0 - <= 5.9

Moxa

ICS-G7752A Series

affected
1.0 - <= 5.9

Moxa

ICS-G7826A Series

affected
1.0 - <= 5.10

Moxa

ICS-G7828A Series

affected
1.0 - <= 5.10

Moxa

ICS-G7848A Series

affected
1.0 - <= 5.9

Moxa

ICS-G7850A Series

affected
1.0 - <= 5.9

Moxa

ICS-G7852A Series

affected
1.0 - <= 5.9

Moxa

IKS-G6524A Series

affected
1.0 - <= 5.10

Moxa

IKS-6726A Series

affected
1.0 - <= 5.9

Moxa

IKS-6728A Series

affected
1.0 - <= 5.9

Moxa

IKS-G6824A Series

affected
1.0 - <= 5.10

Moxa

SDS-3006 Series

affected
1.0 - <= 3.0

Moxa

SDS-3008 Series

affected
1.0 - <= 3.0

Moxa

SDS-3010 Series

affected
1.0 - <= 3.0

Moxa

SDS-3016 Series

affected
1.0 - <= 3.0

Moxa

SDS-G3006 Series

affected
1.0 - <= 3.0

Moxa

SDS-G3008 Series

affected
1.0 - <= 3.0

Moxa

SDS-G3010 Series

affected
1.0 - <= 3.0

Moxa

SDS-G3016 Series

affected
1.0 - <= 3.0

Moxa

PT-7728 Series

affected
1.0 - <= 3.9

Moxa

PT-7828 Series

affected
1.0 - <= 4.0

Moxa

PT-G503 Series

affected
1.0 - <= 5.3

Moxa

PT-G510 Series

affected
1.0 - <= 6.5

Moxa

PT-G7728 Series

affected
1.0 - <= 6.4

Moxa

PT-G7828 Series

affected
1.0 - <= 6.4

Moxa

TN-4500A Series

affected
1.0 - <= 3.13

Moxa

TN-5500A Series

affected
1.0 - <= 3.13

Moxa

TN-G4500 Series

affected
1.0 - <= 5.5

Moxa

TN-G6500 Series

affected
1.0 - <= 5.5

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2024-9137 | CRITICAL (9.4) - Security Vulnerability | QwikSec