Insecure Key Generation in Moxa EDR-G903 Routers
CVE-2012-4694
Currently unrated
Summary
The Moxa EDR-G903 series routers prior to firmware version 2.11 lack a robust source of entropy for generating SSH and SSL keys. This vulnerability can be exploited by man-in-the-middle attackers, allowing them to masquerade as a legitimate device or manipulate the client-server communication by utilizing knowledge of previously installed keys. To mitigate potential risks, users are advised to update their device firmware and enhance the key generation process.
References
Timeline
Vulnerability Reserved
Vulnerability published