CVE-2023-33239: Moxa Tn-4900 Firmware

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.

Affected products

  • Moxa Tn-4900 Firmware: up to and including 1.2.4
  • Moxa Tn-5900 Firmware: up to and including 3.3

Published 2023-08-17. Last modified 2026-06-17.