MEDIUM · 6.1

CVE-2021-39278

Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3,...

Vulnerability Description

Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MoxaWac-2004 Firmware1.7
MoxaWac-2004-
MoxaWac-1001 Firmware2.1
MoxaWac-1001-
MoxaWac-1001-T Firmware2.1
MoxaWac-1001-T-
MoxaOncell G3470A-Lte-Eu Firmware1.7
MoxaOncell G3470A-Lte-Eu-
MoxaOncell G3470A-Lte-Eu-T Firmware1.7
MoxaOncell G3470A-Lte-Eu-T-
MoxaTap-323-Eu-Ct-T Firmware1.3
MoxaTap-323-Eu-Ct-T-
MoxaTap-323-Us-Ct-T Firmware1.3
MoxaTap-323-Us-Ct-T-
MoxaTap-323-Jp-Ct-T Firmware1.3
MoxaTap-323-Jp-Ct-T-
MoxaWdr-3124A-Eu Firmware2.3
MoxaWdr-3124A-Eu-
MoxaWdr-3124A-Eu-T Firmware2.3
MoxaWdr-3124A-Eu-T-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-39278?

CVE-2021-39278 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3,...

How severe is CVE-2021-39278?

CVE-2021-39278 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-39278?

Check the references section above for vendor advisories and patch information. Affected products include: Moxa Wac-2004 Firmware, Moxa Wac-2004, Moxa Wac-1001 Firmware, Moxa Wac-1001, Moxa Wac-1001-T Firmware.