← Back

Oncell Central Manager

oncell_central_manager

Vendor: Moxa • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moxa
1Oncell Central Manager
May 6, 2026
Dec 21, 2015
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.
1Moxa
1Oncell Central Manager
May 6, 2026
Dec 21, 2015
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGr...Show more
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.Show less