High severity8.8NVD Advisory· Published Dec 6, 2018· Updated Jun 17, 2026
CVE-2018-19660
CVE-2018-19660
Description
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/webSettingProfileSecurity can result in running OS commands as the root user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: < 2.2 Build_18082311
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/150535/Moxa-NPort-W2x50A-2.1-OS-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2018/Nov/64nvdExploitMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.