Back
CVE-2019-5138
CRITICAL
An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.
Published: Feb 25, 2020
Modified: Jun 17, 2026
CWE-78
CWE-78
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| moxa | awk-3131a_firmware | 1.13 |
GitHub Security Advisory GHSA-rfr7-5wcc-v3x3
An exploitable command injection vulnerability exists in encrypted diagnostic script...
References (2)
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0927 Exploit, Technical Description, Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0927 Exploit, Technical Description, Third Party Advisory
Risk Scores
CVSS Score
9.9 / 10
EPSS Score
5.16%
Top 8% most likely to be exploited
Threat Score
41.1 / 100
Data Sources
NVD
EPSS
GitHub