← Vulnerability feed

Vulnerability record · CVE-2019-5142 · published 25 February 2020

CVE-2019-5142: Moxa awk-3131a firmware os command injection vulnerability

Moxa · Awk 3131a Firmware

An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.

7.2 CVSS 3.1 High EPSS 6.6% · top 6.4% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0931 ExploitTechnical DescriptionThird Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0931 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2019-5142 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-8363Moxa oncellg3470a-lte firmware permissions and access controls vulnerabilityAn issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, W…EPSS 2.4%9.9CVE-2019-5138Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A spe…EPSS 5.2%9.8CVE-2017-14459Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11…EPSS 13%9.8CVE-2016-8717Moxa awk-3131a firmware hard-coded credentials vulnerabilityAn exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operat…EPSS 2.1%9.1CVE-2016-8721Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running…EPSS 3.3%8.8CVE-2019-5162Moxa awk-3131a firmware improper access control vulnerabilityAn exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13…EPSS 2.6%8.8CVE-2019-5136Moxa awk-3131a firmware improper access control vulnerabilityAn exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially cra…EPSS 2.4%8.8CVE-2019-5140Moxa awk-3131a firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted di…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2019-5142), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.