Vulnerability Details CVE-2016-8720
An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be copied in to Location header of the HTTP response.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.8%
CVSS Severity
CVSS v3 Score 3.1
CVSS v2 Score 4.3
Products affected by CVE-2016-8720
-
cpe:2.3:h:moxa:awk-3131a:-
-
cpe:2.3:o:moxa:awk-3131a_firmware:1.1