CVE-2018-10696
Description
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters and forms/webSetMainRestart URIs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Moxa AWK-3121 firmware 1.14 lacks CSRF protection, allowing attackers to trick administrators into performing unauthorized actions via the web interface.
Vulnerability
The Moxa AWK-3121 wireless access point running firmware version 1.14 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The device's web-based management interface does not implement any anti-CSRF tokens or validation, leaving endpoints such as forms/iw_webSetParameters and forms/webSetMainRestart unprotected. An attacker can exploit this to force an authenticated administrator to execute unintended actions. [1]
Exploitation
An attacker can craft a malicious HTML page or link that, when visited by an authenticated administrator, automatically submits requests to the vulnerable URIs. The attacker does not need to be on the same network or possess any credentials; they only need to trick the victim into interacting with the crafted content (e.g., via email, social engineering, or a compromised website). The victim's active session is reused, so no authentication bypass is required. [1]
Impact
Successful exploitation allows the attacker to perform any action available to the administrator, including modifying device configuration (e.g., wireless settings) or restarting the device. This compromises the integrity and availability of the device, potentially disrupting network services or enabling further attacks. [1]
Mitigation
As of the publication date, no firmware update has been released to address this vulnerability. Users should restrict network access to the web interface to trusted administrators only, use strong session management practices, and educate administrators about the risks of clicking untrusted links while logged into the device. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Moxa/AWK-3121description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/153223/Moxa-AWK-3121-1.14-Information-Disclosure-Command-Execution.htmlmitrex_refsource_MISC
- github.com/samuelhuntley/Moxa_AWK_1121/blob/master/Moxa_AWK_1121mitrex_refsource_MISC
- seclists.org/bugtraq/2019/Jun/8mitremailing-listx_refsource_BUGTRAQ
News mentions
0No linked articles in our index yet.