CVE-2024-0387: Moxa Eds-4008 Firmware

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

Affected products

  • Moxa Eds-4008 Firmware: up to and including 3.2
  • Moxa Eds-4009 Firmware: up to and including 3.2
  • Moxa Eds-4012 Firmware: up to and including 3.2
  • Moxa Eds-4014 Firmware: up to and including 3.2
  • Moxa Eds-g4008 Firmware: up to and including 3.2
  • Moxa Eds-g4012 Firmware: up to and including 3.2
  • Moxa Eds-g4014 Firmware: up to and including 3.2

Published 2024-02-26. Last modified 2026-06-17.