Site icon API Security Blog

Moxa MXsecurity Series Hard-coded JWT Key Authentication Bypass (CVE-2023-33236)

The Moxa MXsecurity Series running on the remote host uses a hard-coded JWT key. An unauthenticated, remote attacker can exploit this, via a specially crafted message, to bypass authentication to perform otherwise restricted operations.Read More

Exit mobile version