### [CVE-2024-9140](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9140) ![](https://img.shields.io/static/v1?label=Product&message=EDF-G1002-BP%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=EDR-8010%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=EDR-G9004%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=EDR-G9010%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=NAT-102%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=OnCell%20G4302-LTE4%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=TN-4900%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-78%3A%20Improper%20Neutralization%20of%20Special%20Elements%20used%20in%20an%20OS%20Command%20(%E2%80%98OS%20Command%20Injection%E2%80%99)&color=brightgreen) ### Description Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s security and functionality. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds