CVE-2017-16727 describes a critical credentials management vulnerability in Moxa NPort W2150A and W2250A devices prior to firmware version 1.11, where the default password is empty. This allows an unauthenticated attacker to remotely access the device with low attack complexity, leading to a complete compromise of wireless traffic confidentiality and integrity. Despite its CVSS score of 9.1 (CRITICAL), there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11CPE matchmatch criteria | cpe:2.3:o:moxa:nport_w2150a_firmware:*:*:*:*:*:*:*:* | ||
< 1.11CPE matchmatch criteria | cpe:2.3:o:moxa:nport_w2250a_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.