

Rewterz Threat Alert – Molerats spear phishing campaign
October 3, 2019
Rewterz Threat Alert – Lazarus Injector – IOC’s
October 4, 2019
Rewterz Threat Alert – Molerats spear phishing campaign
October 3, 2019
Rewterz Threat Alert – Lazarus Injector – IOC’s
October 4, 2019Severity
Medium
Analysis Summary
CVE-2019-10969
An authenticated attacker may abuse the ping feature to execute unauthorized commands on the router, which could allow an attacker to perform remote code execution.
CVE-2019-10963
An unauthenticated attacker may be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.
Impact
- Improper Input Validation
- Improper Access Control
Affected Vendors
Moxa
Affected Products
EDR-810 All versions 5.1 and prior
Remediation
Moxa recommends users upgrade to the latest firmware, v5.2 or later.