# CVE-2024-9138

## Summary

- **CVE ID:** CVE-2024-9138
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-656
- **Published:** Jan 3, 2025
- **Last Modified:** Mar 13, 2026

## Description

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.

## Affected Products

- Moxa — EDR-810 Series (1.0)
- Moxa — EDR-8010 Series (1.0)
- Moxa — EDR-G902 Series (1.0)
- Moxa — EDR-G903 Series (1.0)
- Moxa — EDR-G9004 Series (1.0)
- Moxa — EDR-G9010 Series (1.0)
- Moxa — EDF-G1002-BP Series (1.0)
- Moxa — NAT-102 Series (1.0)
- Moxa — OnCell G4302-LTE4 Series (1.0)
- Moxa — TN-4900 Series (1.0)

## References

- [CNA](https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.15%
- **EPSS Percentile:** 64.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._