← Vulnerability feed

Vulnerability record · CVE-2017-12123 · published 14 May 2018

CVE-2017-12123: Moxa edr-810 firmware insufficiently protected credentials vulnerability

Moxa · Edr 810 Firmware

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.

8.8 CVSS 3.1 High EPSS 1.0% · top 37.7% CWE-522 · Insufficiently protected credentials
8.8CVSS 3.1 base score, v2 3.3
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-16282Moxa edr-810 firmware os command injection vulnerabilityA command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS…EPSS 5.3%8.8CVE-2017-12120Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.3%8.8CVE-2017-12121Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.3%8.8CVE-2017-12125Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.0%8.8CVE-2017-12126Moxa edr-810 firmware cross-site request forgery vulnerabilityAn exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially craft…EPSS 1.00%8.8CVE-2017-14432Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.1%8.8CVE-2017-14433Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.4%8.8CVE-2017-14434Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2017-12123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.