GPU VulnDB

Database/Control plane, storage & DevOps

Moxa NPort W2150A / W2250A wireless device server: A remote attacker can crash or potentially gain code execution

CVE-2024-1220Control plane, storage & DevOpsMPSA-238975curated

Impact

A remote attacker can crash or potentially gain code execution on the device server by sending a crafted payload to its web management service — the built-in web server has a stack-based buffer overflow.

Who can reach it

Remote, over the network — no authentication mentioned as a prerequisite in the vendor advisory; reachability to the web service is sufficient to trigger the overflow.

What to do

Firmware upgrade to the version in Moxa's MPSA-238975 advisory. Flash and reboot each unit; serial sessions on that device drop briefly during the update.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.