CVE-2019-5148: Moxa Awk-3131a Firmware
High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.
Affected products
- Moxa Awk-3131a Firmware: version 1.13 only
Published 2020-02-25. Last modified 2026-06-17.