VendorsMoxaedr-g903all versions
Vulnerabilities

Moxa EDR-G903

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2020-28144
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
Published 2021-02-03 · Modified
9.8EPSS 0.026
CVE-2020-14511
Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).
Published 2020-07-15 · Modified
9.8EPSS 0.014
CVE-2016-0879
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
Published 2016-05-31 · Modified
7.8EPSS 0.022
CVE-2016-0877
Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (memory consumption) by executing the ping function.
Published 2016-05-31 · Modified
7.8EPSS 0.018
CVE-2016-0878
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.
Published 2016-05-31 · Modified
7.8EPSS 0.018
CVE-2012-4694
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
Published 2013-02-15 · Modified
7.6EPSS 0.011
CVE-2016-0875
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
Published 2016-05-31 · Modified
7.5EPSS 0.018
CVE-2016-0876
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
Published 2016-05-31 · Modified
7.5EPSS 0.011
CVE-2023-4452
Web Server Buffer Overflow Vulnerability
Published 2023-11-01 · Modified
7.5EPSS 0.004
CVE-2012-4712
Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.
Published 2013-02-15 · Modified
5.0EPSS 0.019