Partly critical router holes endanger industrial networks
Summary
In January 2025 the industrial network equipment supplier Moxa warned of two holes in routers and security appliances used, among other places, in energy facilities. CVE-2024-9138 is based on hard-coded credentials and gives authenticated attackers root privileges; the critical CVE-2024-9140 allows system commands to be injected. Firmware updates were available for several model series, while for others there were only workarounds or a referral to support.
Ideas
- Hard-coded credentials are a design flaw, not a configuration matter.
- Industrial networks use devices whose compromise can have physical consequences.
- A patch was not available for all models.
- As a workaround, Moxa advised not making devices reachable from the internet and restricting SSH.
Insights
- Because industrial IT is patched slowly, network segmentation is mandatory there.
- Manufacturers with built-in access endanger entire industries.
Facts
- The firmware was fixed in version 3.14 for the EDR-8010 and EDR-G9010, among others.
- The holes were discovered by security researcher Lars Haulin.
References
Critique
- The report does not say whether the holes had already been exploited.
Recommendations
- Strictly separate OT networks from the internet and from office IT.
- Use an IPS or anomaly detection in industrial networks, as Moxa recommends.
Links to the original source and the Web Archive open in a new tab.