Medium severity4.3NVD Advisory· Published Apr 13, 2017· Updated May 13, 2026
CVE-2016-8720
CVE-2016-8720
Description
An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be copied in to Location header of the HTTP response.
Affected products
2- cpe:2.3:o:moxa:awk-3131a_firmware:1.1:*:*:*:*:*:*:*
- Moxa/AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/clientv5Range: 1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.talosintelligence.com/reports/TALOS-2016-0234/nvdExploitMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.