CVE-2018-10699
Description
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_privatePass" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated command injection in Moxa AWK-3121 certfile upload via POST parameter iw_privatePass allows full device compromise.
Vulnerability
The Moxa AWK-3121 wireless access point firmware version 1.14 contains a command injection vulnerability in the certfile upload functionality. The POST parameter iw_privatePass is not sanitized before being processed by the device. An attacker can inject arbitrary operating system commands by including shell metacharacters (e.g., ;, |, ` ``) in this parameter value. No authentication is required to reach this code path because the upload endpoint is exposed to network-level attackers. Affected versions include AWK-3121 firmware 1.14; earlier releases may also be vulnerable [1].
Exploitation
An attacker with network access to the device can craft a POST request to the certfile upload endpoint. The iw_privatePass parameter is the injection point; including shell metacharacters followed by arbitrary commands results in command execution as the root or system user. No prior authentication or session is required, and no user interaction on the target device is necessary. The attack can be performed by sending a single crafted HTTP request [1].
Impact
Successful exploitation gives the attacker full remote command execution on the Moxa AWK-3121 with root privileges. This leads to complete compromise of the device confidentiality, integrity, and availability. An attacker can install persistent backdoors, reconfigure the wireless network, exfiltrate sensitive data, or use the device as a pivot point to attack other network hosts [1].
Mitigation
Moxa has released firmware updates addressing this issue; users should upgrade to version 1.19 or later. If upgrading is not immediately possible, restrict network access to the administrative web interface to trusted IPs only, and disable the certfile upload functionality if not required. The AWK-3121 is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Moxa/AWK-3121description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/153223/Moxa-AWK-3121-1.14-Information-Disclosure-Command-Execution.htmlmitrex_refsource_MISC
- github.com/samuelhuntley/Moxa_AWK_1121/blob/master/Moxa_AWK_1121mitrex_refsource_MISC
- seclists.org/bugtraq/2019/Jun/8mitremailing-listx_refsource_BUGTRAQ
News mentions
0No linked articles in our index yet.