Insecure Key Generation in Moxa EDR-G903 Routers
CVE-2012-4694

Currently unrated

Key Information:

Vendor
Moxa
Vendor
CVE Published:
15 February 2013

Summary

The Moxa EDR-G903 series routers prior to firmware version 2.11 lack a robust source of entropy for generating SSH and SSL keys. This vulnerability can be exploited by man-in-the-middle attackers, allowing them to masquerade as a legitimate device or manipulate the client-server communication by utilizing knowledge of previously installed keys. To mitigate potential risks, users are advised to update their device firmware and enhance the key generation process.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.