VYPR
Critical severity10.0NVD Advisory· Published Apr 11, 2018· Updated Jun 17, 2026

CVE-2017-14459

CVE-2017-14459

Description

An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Moxa/AWK-3131Allm-fuzzy
    Range: 1.4 to 1.7
  • Talos/Moxav5
    Range: Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client versions 1.4 - 1.9. In addition, versions prior to 1.4 appear similarly vulnerable to injection, but not as easily exploitable (described below). Other models in the AWK product line may likewise be vulnerable but have not been tested.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.