Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpp3-j837-w9p4

Опубликовано: 02 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.2

Описание

A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.

A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.

EPSS

Процентиль: 73%
0.00757
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
10 месяцев назад

A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.

CVSS3: 9.1
fstec
10 месяцев назад

Уязвимость веб-интерфейса микропрограммного обеспечения сетевых устройств Moxa серий EDF-G1002-BP, EDR-810, EDR-8010, EDR-G9004, EDR-G9010, NAT-102, TN-4900 и OnCell G4302-LTE4, позволяющая нарушителю выполнить произвольные команды через настройки NTP и получить полный контроль над устройством

EPSS

Процентиль: 73%
0.00757
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-78