Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Moxa Warns Users of Serious Vulnerabilities in Cellular and Secure Routers
Global Security

Moxa Warns Users of Serious Vulnerabilities in Cellular and Secure Routers

AdminBy AdminJanuary 7, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 7, 2025Ravi LakshmananVulnerability / Network Security

Taiwan’s Moxa has warned of two security vulnerabilities affecting cellular routers, secure routers, and network security devices that could allow elevation of privilege and command execution.

The list of vulnerabilities is as follows –

  • CVE-2024-9138 (CVSS Score 4.0: 8.6) – A hard-coded credential vulnerability that could allow an authenticated user to elevate privileges and gain root access to the system, leading to system compromise, unauthorized modification, data disclosure, or service failure
  • CVE-2024-9140 (CVSS Score 4.0: 9.3) – The vulnerability allows attackers to use special characters to bypass input restrictions, which could lead to unauthorized command execution

The vulnerabilities, reported by security researcher Lars Howlin, affect the following products and firmware versions –

  • CVE-2024-9138 – EDR-810 series (Firmware version 5.12.37 and earlier), EDR-8010 series (Firmware version 3.13.1 and earlier), EDR-G902 series (Firmware version 5.7.25 and earlier), EDR-G902 series (Firmware version 5.7.25 and earlier), EDR-G9004 series (firmware version 3.13.1 and earlier), EDR-G9010 series (firmware version 3.13.1 and earlier), EDF-G1002-BP series (firmware version 3.13.1 and earlier), NAT-102 series (firmware version 1.0.5 and earlier) , OnCell G4302-LTE4 series (Firmware version 3.13 and earlier) and TN-4900 Series (firmware version 3.13 and earlier)
  • CVE-2024-9140 – EDR-8010 series (Firmware version 3.13.1 and earlier), EDR-G9004 series (Firmware version 3.13.1 and earlier), EDR-G9010 series (Firmware version 3.13.1 and earlier), EDF-G1002-BP series ( Firmware version 3.13.1 and earlier), NAT-102 series (firmware version 1.0.5 and earlier), OnCell G4302-LTE4 series (firmware version 3.13 and earlier) and TN-4900 series (firmware version 3.13 and earlier)
Cyber ​​security

Patches were available for the following versions –

  • EDR-810 Series (Upgrade to firmware version 3.14 or later)
  • EDR-8010 Series (Update firmware to 3.14 or later)
  • EDR-G902 Series (Update firmware to 3.14 or later)
  • EDR-G903 Series (Update firmware to 3.14 or later)
  • EDR-G9004 series (Update firmware to version 3.14 or later)
  • EDR-G9010 Series (Update firmware to 3.14 or later)
  • EDF-G1002-BP series (Upgrade to firmware version 3.14 or later)
  • NAT-102 series (no official patch)
  • OnCell G4302-LTE4 Series (Contact Moxa Technical Support)
  • TN-4900 Series (Contact Moxa Technical Support)

As a mitigation measure, it is recommended to ensure that devices are not exposed to the Internet, limit SSH access to trusted IP addresses and networks using firewall rules or TCP wrappers, and take measures to detect and prevent exploit attempts.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.