CVE-2016-0877 describes a memory leak vulnerability affecting Moxa Secure Router EDR-G903 devices running firmware versions prior to 3.4.12. This flaw allows remote attackers to trigger a denial of service by repeatedly executing the ping function, leading to excessive memory consumption. Rated 7.5 HIGH on CVSS, it is a network-exploitable vulnerability with low attack complexity and high impact on availability, requiring no user interaction or privileges. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.12CPE matchmatch criteria | cpe:2.3:o:moxa:edr-g903_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.