CVE-2010-4741 describes a stack-based buffer overflow vulnerability in MDMUtil.dll within MDMTool.exe of Moxa Device Manager, specifically versions prior to 2.3. This flaw allows remote MDM Gateways to execute arbitrary code by sending specially crafted data over TCP port 54321. Rated with a CVSS score of 9.3 (Critical), this vulnerability is remotely exploitable with medium attack complexity and requires no authentication, leading to complete compromise of confidentiality, integrity, and availability. Its high FAUCET Risk Score of 98/100 further emphasizes its severe potential impact. While not listed in CISA's KEV catalog, exploit code is publicly available, including a Metasploit module, indicating a clear path for exploitation. Despite this, there is no recorded community discussion or media coverage, suggesting it may not be actively exploited in the wild or widely known among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:moxa:device_manager:*:*:*:*:*:*:*:* | ||
<= 2.1CPE matchmatch criteria | cpe:2.3:a:moxa:mdm_tool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.