CVE-2017-7917: Moxa Oncell 5004-Hspa Firmware
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.
Affected products
- Moxa Oncell 5004-Hspa Firmware: up to and including -
- Moxa Oncell 5104-Hsdpa Firmware: up to and including -
- Moxa Oncell 5104-Hspa Firmware: up to and including -
- Moxa Oncell g3110-Hsdpa Firmware: up to and including 1.2
- Moxa Oncell g3110-Hspa Firmware: up to and including 1.3
- Moxa Oncell g3150-Hsdpa Firmware: up to and including 1.4
Published 2017-05-29. Last modified 2026-06-17.