“Open sesame”: Industrial network gear hackable with the right username

Posted on Apr 6, 2018

“Open sesame”: Industrial network gear hackable with the right username

This week, two separate security alerts have revealed major holes in devices from Moxa, an industrial automation networking company. In one case, attackers could potentially send commands to a device’s operating system by using them as a username in a login attempt. In another, the private key for a Web server used to manage network devices could be retrieved through an HTTP GET request.

Source: arstechnica.com