CVSS v3
9.8
CRITICAL
EPSS Score
19.8 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.
Technical details
- Published
- 2018-04-11
- Exploit-DB
- EDB-44398
Frequently asked questions
What is CVE-2017-14459?
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.
Is CVE-2017-14459 actively exploited?
Active exploitation of CVE-2017-14459 has not been confirmed. The EPSS score is 19.8%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2017-14459?
CVE-2017-14459 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2017-14459 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2017 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).