VYPR

Nport W2x50a Firmware

by Moxa

CVEs (2)

  • CVE-2018-19660HigDec 6, 2018
    risk 0.60cvss 8.8epss 0.29

    An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/webSettingProfileSecurity can result in running OS commands…

  • CVE-2018-19659HigDec 6, 2018
    risk 0.58cvss 8.8epss 0.04

    An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/net_WebPingGetValue can result in running OS commands as…