CVE-2024-9140: Moxa Edf-g1002-Bp Series

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s security and functionality.

Affected products

  • Moxa Edf-g1002-Bp Series: from 1.0, up to and including 3.13.1
  • Moxa Edr-8010 Series: from 1.0, up to and including 3.13.1
  • Moxa Edr-g9004 Series: from 1.0, up to and including 3.13.1
  • Moxa Edr-g9010 Series: from 1.0, up to and including 3.13.1
  • Moxa Nat-102 Series: from 1.0, up to and including 1.0.5
  • Moxa Oncell g4302-LTE4 Series: from 1.0, up to and including 3.13
  • Moxa Tn-4900 Series: from 1.0, up to and including 3.13

Published 2025-01-03. Last modified 2026-06-17.