VYPR
Unrated severityNVD Advisory· Published Jun 7, 2019· Updated Aug 5, 2024

CVE-2018-10696

CVE-2018-10696

Description

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters and forms/webSetMainRestart URIs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Moxa AWK-3121 firmware 1.14 lacks CSRF protection, allowing attackers to trick administrators into performing unauthorized actions via the web interface.

Vulnerability

The Moxa AWK-3121 wireless access point running firmware version 1.14 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The device's web-based management interface does not implement any anti-CSRF tokens or validation, leaving endpoints such as forms/iw_webSetParameters and forms/webSetMainRestart unprotected. An attacker can exploit this to force an authenticated administrator to execute unintended actions. [1]

Exploitation

An attacker can craft a malicious HTML page or link that, when visited by an authenticated administrator, automatically submits requests to the vulnerable URIs. The attacker does not need to be on the same network or possess any credentials; they only need to trick the victim into interacting with the crafted content (e.g., via email, social engineering, or a compromised website). The victim's active session is reused, so no authentication bypass is required. [1]

Impact

Successful exploitation allows the attacker to perform any action available to the administrator, including modifying device configuration (e.g., wireless settings) or restarting the device. This compromises the integrity and availability of the device, potentially disrupting network services or enabling further attacks. [1]

Mitigation

As of the publication date, no firmware update has been released to address this vulnerability. Users should restrict network access to the web interface to trusted administrators only, use strong session management practices, and educate administrators about the risks of clicking untrusted links while logged into the device. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.