CVE-2024-9137: Moxa Edf-g1002-Bp

Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.

The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.

Affected products

  • Moxa Edf-g1002-Bp: from 1.0, up to and including 3.12.1
  • Moxa Edf-g1002-Bp Series: from 1.0, up to and including 3.12.1
  • Moxa Edr-8010: from 1.0, up to and including 3.12.1
  • Moxa Edr-8010 Series: from 1.0, up to and including 3.12.1
  • Moxa Edr-g9004: from 1.0, up to and including 3.12.1
  • Moxa Edr-g9004 Series: from 1.0, up to and including 3.12.1
  • Moxa Edr-g9010: from 1.0, up to and including 3.12.1
  • Moxa Edr-g9010 Series: from 1.0, up to and including 3.12.1
  • Moxa Eds-405a Series: from 1.0, up to and including 3.14
  • Moxa Eds-408a Series: from 1.0, up to and including 3.12
  • Moxa Eds-505a Series: from 1.0, up to and including 3.11
  • Moxa Eds-508a Series: from 1.0, up to and including 3.11
  • Moxa Eds-510a Series: from 1.0, up to and including 3.12
  • Moxa Eds-510e Series: from 1.0, up to and including 5.5
  • Moxa Eds-516a Series: from 1.0, up to and including 3.11
  • Moxa Eds-518a Series: from 1.0, up to and including 3.11
  • Moxa Eds-518e Series: from 1.0, up to and including 6.3
  • Moxa Eds-528e Series: from 1.0, up to and including 6.3
  • Moxa Eds-608 Series: from 1.0, up to and including 3.12
  • Moxa Eds-611 Series: from 1.0, up to and including 3.12
  • Moxa Eds-616 Series: from 1.0, up to and including 3.12
  • Moxa Eds-619 Series: from 1.0, up to and including 3.12
  • Moxa Eds-g508e Series: from 1.0, up to and including 6.4
  • Moxa Eds-g509 Series: from 1.0, up to and including 3.10
  • Moxa Eds-g512e Series: from 1.0, up to and including 6.4
  • and 42 more

Published 2024-10-14. Last modified 2026-06-17.