Moxa EDR-G903 Secure Router Vulnerabilities (Update A)
Moxa EDR-G903 Secure Router contains multiple vulnerabilities in input validation and credential handling. Versions V3.4.11 and earlier are affected. The vulnerabilities allow unauthenticated attackers with network access to read sensitive data such as certificates and credentials (CWE-256, CWE-284), leak sensitive information through error messages (CWE-226), or trigger denial of service via resource exhaustion or buffer handling issues (CWE-401, CWE-400). No patch is available; the product is end-of-life or will not be updated.
- Network access to the EDR-G903 management port(s) (typically port 80, 443, or 502)
- No authentication required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/bd1fc6e2-7764-4230-88ec-501524cb4bb8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.