Manuel 'HonkHase' Atug<p><a href="https://chaos.social/tags/Moxa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Moxa</span></a> warns of two flaws in its <a href="https://chaos.social/tags/routers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>routers</span></a> and security <a href="https://chaos.social/tags/appliances" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appliances</span></a> that enable privilege escalation and remote command execution.</p><p>"Moxa addressed privilege escalation and OS command injection <a href="https://chaos.social/tags/vulnerabilities" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vulnerabilities</span></a> in cellular routers, secure routers, and network security appliances."</p><p>CVE-2024-9138 (CVSS 4.0 score: 8.6)<br>CVE-2024-9140 (CVSS 4.0 score: 9.3)</p><p><a href="https://chaos.social/tags/KRITIS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KRITIS</span></a> <a href="https://chaos.social/tags/OT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OT</span></a> <a href="https://chaos.social/tags/RCE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RCE</span></a><br><a href="https://securityaffairs.com/172770/ics-scada/moxa-router-flaws-risks-to-industrial-environmets.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">securityaffairs.com/172770/ics</span><span class="invisible">-scada/moxa-router-flaws-risks-to-industrial-environmets.html</span></a></p>