CVE-2016-8721: Moxa Awk-3131a Firmware

Critical severity, CVSS 9.1. EPSS: 3.3% chance of exploitation in the next 30 days.

An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete compromise of the vulnerable device. An attacker can exploit this vulnerability remotely.

Affected products

  • Moxa Awk-3131a Firmware: version 1.1 only

Published 2017-04-20. Last modified 2026-06-17.