Reflected XSS Vulnerability in MOXA Devices
CVE-2021-39278
6.1MEDIUM
What is CVE-2021-39278?
Certain MOXA network devices are vulnerable to reflected Cross-Site Scripting (XSS) attacks through the Config Import menu. This vulnerability can be exploited by an attacker who tricks a user into visiting a specially crafted URL, which could lead to unauthorized access or manipulation of session information. Affected devices include various models across WAC, OnCell, TAP, and WDR series, potentially putting users at risk if proper security measures are not implemented.