CVE-2012-4694: Moxa Edr-g903
High severity, CVSS 7.6. EPSS: 1.1% chance of exploitation in the next 30 days.
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
Affected products
- Moxa Edr-g903
- Moxa Edr g903 Firmware: up to and including 2.2; version 1.0 only; version 2.0 only; version 2.1 only
Published 2013-02-15. Last modified 2026-06-16.