XSS Vulnerability in Moxa AWK-3121 Series Devices
CVE-2018-10700
6.1MEDIUM
What is CVE-2018-10700?
An XSS vulnerability exists in Moxa AWK-3121 devices running version 1.19, where an attacker can exploit the functionality allowing administrators to change the device name. By injecting a payload into the POST parameter 'iw_board_deviceName', an unauthorized user can execute arbitrary scripts within the context of the user’s session, potentially leading to data theft and other malicious activities.