An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0928 | exploit third party advisory technical description |