← Vulnerability feed

Vulnerability record · CVE-2019-5139 · published 25 February 2020

CVE-2019-5139: Moxa awk-3131a firmware hard-coded credentials vulnerability

Moxa · Awk 3131a Firmware

An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

7.1 CVSS 3.1 High EPSS 0.32% · top 76.8% CWE-798 · Hard-coded credentials
7.1CVSS 3.1 base score, v2 3.6
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0928 ExploitTechnical DescriptionThird Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0928 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2019-5139 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-8363Moxa oncellg3470a-lte firmware permissions and access controls vulnerabilityAn issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, W…EPSS 2.4%9.9CVE-2019-5138Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A spe…EPSS 5.2%9.8CVE-2017-14459Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11…EPSS 13%9.8CVE-2016-8717Moxa awk-3131a firmware hard-coded credentials vulnerabilityAn exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operat…EPSS 2.1%9.1CVE-2016-8721Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running…EPSS 3.3%8.8CVE-2019-5162Moxa awk-3131a firmware improper access control vulnerabilityAn exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13…EPSS 2.6%8.8CVE-2019-5140Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted di…EPSS 2.8%8.8CVE-2019-5153Moxa awk-3131a firmware stack-based buffer overflow vulnerabilityAn exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1…EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2019-5139), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.