CVE-2018-10690: Moxa Awk-3121 Firmware

High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allows an attacker to sniff the traffic easily and allows an attacker to compromise sensitive data such as credentials.

Affected products

  • Moxa Awk-3121 Firmware: version 1.14 only

Published 2019-06-07. Last modified 2026-06-17.