← Vulnerability feed

Vulnerability record · CVE-2016-8717 · published 2 April 2018

CVE-2016-8717: Moxa awk-3131a firmware hard-coded credentials vulnerability

Moxa · Awk 3131a Firmware

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.

9.8 CVSS 3.1 Critical EPSS 2.1% · top 19.0% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score, v2 10.0
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8717 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-8363Moxa oncellg3470a-lte firmware permissions and access controls vulnerabilityAn issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, W…EPSS 2.4%9.9CVE-2019-5138Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A spe…EPSS 5.2%9.8CVE-2017-14459Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11…EPSS 13%9.1CVE-2016-8721Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running…EPSS 3.3%8.8CVE-2019-5162Moxa awk-3131a firmware improper access control vulnerabilityAn exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13…EPSS 2.6%8.8CVE-2019-5136Moxa awk-3131a firmware improper access control vulnerabilityAn exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially cra…EPSS 2.4%8.8CVE-2019-5140Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted di…EPSS 2.8%8.8CVE-2019-5141Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted i…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2016-8717), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.