Back to Database
Status published
High
CVE-2018-11427
CSRF tokens are not used in the web application of...
Vulnerability Description
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-11427
Credits & Attribution
No credits recorded in the NVD database.
More from moxa
View All →CVE-2022-27048
A vulnerability has been discovered in Moxa MGate which allows...
High
7.4
CVE-2021-46560
The firmware on Moxa TN-5900 devices through 3.1 allows command...
Critical
9.8
CVE-2021-46559
The firmware on Moxa TN-5900 devices through 3.1 has a...
High
7.5
CVE-2021-46082
Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol...
High
7.5
CVE-2021-39279
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This...
High
8.8
Affected Vendor
moxa
View all reports →Affected Software
oncell g3150-hspa firmware, oncell g3150-hspa-t firmware
Vulnerable Versions:
0
Timeline
Official Publish:
July 3rd, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.