CVE-2018-11421 affects Moxa OnCell G3100-HSPA Series devices running firmware version 1.6 Build 17100315 and prior. The vulnerability stems from a proprietary monitoring protocol that lacks confidentiality, integrity, and authenticity controls, transmitting all data in plaintext. This critical vulnerability (CVSS 9.8) allows remote, unauthenticated attackers to disclose sensitive information, including administrator passwords, and potentially retrieve additional data through memory leakages. Despite its high severity, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6CPE matchmatch criteria | cpe:2.3:o:moxa:oncell_g3150-hspa_firmware:*:*:*:*:*:*:*:* | ||
<= 1.6CPE matchmatch criteria | cpe:2.3:o:moxa:oncell_g3150-hspa-t_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.