CVE-2019-5165: Moxa Awk-3131a Firmware

High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.

An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

Affected products

  • Moxa Awk-3131a Firmware: version 1.13 only

Published 2020-02-25. Last modified 2026-06-17.