← Vulnerability feed

Vulnerability record · CVE-2019-5137 · published 25 February 2020

CVE-2019-5137: Moxa awk-3131a firmware hard-coded credentials vulnerability

Moxa · Awk 3131a Firmware

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

7.5 CVSS 3.1 High EPSS 2.3% · top 17.5% CWE-321 · CWE-321CWE-798 · Hard-coded credentials
7.5CVSS 3.1 base score, v2 5.0
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0926 ExploitTechnical DescriptionThird Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0926 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2019-5137 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-8363Moxa oncellg3470a-lte firmware permissions and access controls vulnerabilityAn issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, W…EPSS 2.4%9.9CVE-2019-5138Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A spe…EPSS 5.2%9.8CVE-2017-14459Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11…EPSS 13%9.8CVE-2016-8717Moxa awk-3131a firmware hard-coded credentials vulnerabilityAn exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operat…EPSS 2.1%9.1CVE-2016-8721Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running…EPSS 3.3%8.8CVE-2019-5162Moxa awk-3131a firmware improper access control vulnerabilityAn exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13…EPSS 2.6%8.8CVE-2019-5143Moxa awk-3131a firmware classic buffer overflow vulnerabilityAn exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A speci…EPSS 4.5%8.8CVE-2019-5141Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted i…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2019-5137), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.