Product support

Security Advisories

SUMMARY

NPort W2150A/NPort W2250A Serial Device Servers Vulnerabilities

  • Version: 1.0
  • Release Date: Dec 13, 2018
  • Reference:
    • CVE-2018-19659, CVE-2018-19660

Multiple product vulnerabilities were identified in NPort W2150A and NPort W2250A Serial Device Servers. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Authenticated OS Command Injection (CVE-2018-19659) Web server ping function can allow users with administrative privileges to circumvent the Linux operating system's user access controls.
2 Authenticated OS Command Injection (CVE-2018-19660) Web server WLAN profile properties function can allow users with administrative privileges to circumvent the Linux operating system's user access controls.
AFFECTED PRODUCTS AND SOLUTIONS

Affected Products:

The affected products and firmware versions are shown below.

Product Series Affected Versions
NPort W2150A/NPort W2250A Series Firmware Version 2.1 or prior

 

Solutions:

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below.

Product Series Solutions
NPort W2150A/NPort W2250A Series Please download the new firmware/software here.

 

Revision History:

VERSION DESCRIPTION RELEASE DATE
1.0 First Release Dec 13, 2018

 

Relevant Products

NPort W2150A/W2250A Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag