CVE-2018-10692: Moxa Awk-3121 Firmware

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to steal the cookie very easily.

Affected products

  • Moxa Awk-3121 Firmware: version 1.14 only

Published 2019-06-07. Last modified 2026-06-17.