VYPR
Medium severity4.3NVD Advisory· Published Apr 13, 2017· Updated May 13, 2026

CVE-2016-8720

CVE-2016-8720

Description

An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be copied in to Location header of the HTTP response.

Affected products

2
  • cpe:2.3:o:moxa:awk-3131a_firmware:1.1:*:*:*:*:*:*:*
  • Moxa/AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/clientv5
    Range: 1.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.