CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.
References
Link | Resource |
---|---|
https://github.com/klsecservices/Advisories/blob/master/KL-MOXA-2018-106.md | Third Party Advisory |
https://github.com/klsecservices/Advisories/blob/master/KL-MOXA-2018-106.md | Third Party Advisory |
Configurations
History
21 Nov 2024, 03:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/klsecservices/Advisories/blob/master/KL-MOXA-2018-106.md - Third Party Advisory |
Information
Published : 2019-07-03 15:15
Updated : 2024-11-21 03:43
NVD link : CVE-2018-11427
Mitre link : CVE-2018-11427
CVE.ORG link : CVE-2018-11427
JSON object : View
Products Affected
moxa
- oncell_g3150-hspa
- oncell_g3150-hspa_firmware
- oncell_g3150-hspa-t
- oncell_g3150-hspa-t_firmware
CWE
CWE-352
Cross-Site Request Forgery (CSRF)