VendorsMoxaoncell_central_managerall versions
Vulnerabilities

Moxa Oncell Central Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-6480
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.
Published 2015-12-21 · Modified
8.3EPSS 0.018
CVE-2015-6481
The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.
Published 2015-12-21 · Modified
8.3EPSS 0.017