← Vulnerability feed

Vulnerability record · CVE-2017-12127 · published 14 May 2018

CVE-2017-12127: Moxa edr-810 firmware insufficiently protected credentials vulnerability

Moxa · Edr 810 Firmware

A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.

4.4 CVSS 3.1 Medium EPSS 0.43% · top 64.3% CWE-522 · Insufficiently protected credentials
4.4CVSS 3.1 base score, v2 2.1
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-16282Moxa edr-810 firmware os command injection vulnerabilityA command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS…EPSS 5.3%8.8CVE-2017-12121Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.3%8.8CVE-2017-12125Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.0%8.8CVE-2017-14433Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.4%8.8CVE-2017-12123Moxa edr-810 firmware insufficiently protected credentials vulnerabilityAn exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 1703031…EPSS 1.0%8.8CVE-2017-12120Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.3%8.8CVE-2017-12126Moxa edr-810 firmware cross-site request forgery vulnerabilityAn exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially craft…EPSS 1.00%8.8CVE-2017-14434Moxa edr-810 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP P…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2017-12127), CISA KEV, FIRST EPSS (scores of 2026-10-10). This page is refreshed as NVD updates the record.