An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.
Conclusion & alert: CVE-2019-5142 is rated High Exploit Risk (81.2/100): CVSS High severity, with high exploitation likelihood (EPSS 6.89%, 93th percentile).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +4.79% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2019-5142
Exploit prediction scoring system (EPSS) score for CVE-2019-5142
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).