AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Moxa
MO
Platform

Moxa

Industrial serial servers, Ethernet switches, cellular gateways, and Edge computing for IIoT environments.

https://www.moxa.com →
260
Total CVEs
0
Resources
59
CRIT
145
HIGH
44
MED
2
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
59 / 260
CVE-2021-38454CRITICAL

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Oct 12, 2021
10.0
CVE-2017-14459CRITICAL

An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.

Apr 11, 2018
10.0
CVE-2016-8363CRITICAL

An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. User is able to execute arbitrary OS commands on the server.

Feb 13, 2017
10.0
CVE-2019-5138CRITICAL

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
9.9
CVE-2024-9140CRITICAL

Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s security and functionality.

Jan 3, 2025
9.8
CVE-2023-28697CRITICAL

Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.

Apr 27, 2023
9.8
CVE-2021-40390CRITICAL

An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.

Apr 14, 2022
9.8
CVE-2021-32976CRITICAL

Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to initiate a denial-of-service attack and execute arbitrary code.

Apr 1, 2022
9.8
CVE-2021-32974CRITICAL

Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.

Apr 1, 2022
9.8
CVE-2021-46560CRITICAL

The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.

Jan 26, 2022
9.8
CVE-2021-38458CRITICAL

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Oct 12, 2021
9.8
CVE-2021-38456CRITICAL

A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords

Oct 12, 2021
9.8
CVE-2020-28144CRITICAL

Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.

Feb 3, 2021
9.8
CVE-2020-25196CRITICAL

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.

Dec 23, 2020
9.8
CVE-2020-25153CRITICAL

The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.

Dec 23, 2020
9.8
CVE-2020-23639CRITICAL

A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.

Nov 2, 2020
9.8
CVE-2020-7007CRITICAL

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of service.

Mar 24, 2020
9.8
CVE-2020-6991CRITICAL

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.

Mar 24, 2020
9.8
CVE-2020-6981CRITICAL

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication.

Mar 24, 2020
9.8
CVE-2020-6995CRITICAL

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.

Mar 24, 2020
9.8
CVE-2020-6985CRITICAL

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code for access to the console.

Mar 24, 2020
9.8
CVE-2020-6989CRITICAL

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows remote attackers to cause a denial-of-service condition or execute arbitrary code.

Mar 24, 2020
9.8
CVE-2019-9099CRITICAL

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).

Mar 11, 2020
9.8
CVE-2019-9096CRITICAL

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by brute-forcing account passwords.

Mar 11, 2020
9.8
CVE-2019-9095CRITICAL

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker may be able to intercept weakly encrypted passwords and gain administrative access.

Mar 11, 2020
9.8
CVE-2018-11425CRITICAL

Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11424.

Jul 3, 2019
9.8
CVE-2018-11422CRITICAL

Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. Any commands (including device reboot, configuration download or upload, or firmware upgrade) are accepted and executed by the device without authentication.

Jul 3, 2019
9.8
CVE-2018-11421CRITICAL

Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. The protocol is vulnerable to remote unauthenticated disclosure of sensitive information, including the administrator's password. Under certain conditions, it's also possible to retrieve additional information, such as content of HTTP requests to the device, or the previously used password, due to memory leakages.

Jul 3, 2019
9.8
CVE-2018-11420CRITICAL

There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 17042015 and prio,r a different vulnerability than CVE-2018-11423.

Jul 3, 2019
9.8
CVE-2018-11426CRITICAL

A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication and access the web interface to use all its functions except for password change.

Jul 3, 2019
9.8
CVE-2018-10698CRITICAL

An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect to the TELNET daemon using the default credentials if they have not been changed by the user.

Jun 7, 2019
9.8
CVE-2019-6526CRITICAL

Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacker to capture sensitive data such as an administrative password.

Apr 15, 2019
9.8
CVE-2019-6563CRITICAL

Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.

Mar 5, 2019
9.8
CVE-2019-6557CRITICAL

Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution.

Mar 5, 2019
9.8
CVE-2019-6524CRITICAL

Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.

Mar 5, 2019
9.8
CVE-2018-18396CRITICAL

Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
9.8
CVE-2018-18395CRITICAL

Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
9.8
CVE-2018-18394CRITICAL

Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
9.8
CVE-2018-18393CRITICAL

Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
9.8
CVE-2016-8717CRITICAL

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.

Apr 2, 2018
9.8
CVE-2018-5455CRITICAL

A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.

Mar 5, 2018
9.8
CVE-2017-12729CRITICAL

A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can exploit this vulnerability to access SoftCMS without knowing the user's password.

Jan 18, 2018
9.8
CVE-2017-13701CRITICAL

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering method.

Nov 23, 2017
9.8
CVE-2017-7915CRITICAL

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. An attacker can freely use brute force to determine parameters needed to bypass authentication.

May 29, 2017
9.8
CVE-2017-7913CRITICAL

A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application's configuration file contains parameters that represent passwords in plaintext.

May 29, 2017
9.8
CVE-2016-9369CRITICAL

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Firmware can be updated over the network without authentication, which may allow remote code execution.

Feb 13, 2017
9.8
CVE-2016-9366CRITICAL

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. An attacker can freely use brute force to determine parameters needed to bypass authentication.

Feb 13, 2017
9.8
CVE-2016-9361CRITICAL

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Administration passwords can be retried without authenticating.

Feb 13, 2017
9.8
CVE-2016-9333CRITICAL

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTION).

Feb 13, 2017
9.8
CVE-2016-5799CRITICAL

Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

Aug 24, 2016
9.8
CVE-2016-5792CRITICAL

SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.

Aug 8, 2016
9.8
CVE-2016-5804CRITICAL

Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.

Jul 15, 2016
9.8
CVE-2016-4503CRITICAL

Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors related to reading a cookie parameter containing a UserId value.

Jul 12, 2016
9.8
CVE-2024-9137CRITICAL

The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.

Oct 14, 2024
9.4
CVE-2021-25848CRITICAL

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available length via a crafted lldp packet.

May 10, 2021
9.1
CVE-2021-25847CRITICAL

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to controllable loop counter variable via a crafted lldp packet.

May 10, 2021
9.1
CVE-2019-6522CRITICAL

Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device reboot.

Mar 5, 2019
9.1
CVE-2017-16727CRITICAL

A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort W2250A versions prior to 1.11. The default password is empty on the device. An unauthorized user can access the device without a password. An unauthorized user has the ability to completely compromise the confidentiality and integrity of the wireless traffic.

Dec 22, 2017
9.1
CVE-2016-8721CRITICAL

An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete compromise of the vulnerable device. An attacker can exploit this vulnerability remotely.

Apr 20, 2017
9.1
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2021-38454CRITICAL
10.0
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 …Oct 12, 2021›
CVE-2017-14459CRITICAL
10.0
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login funct…Apr 11, 2018›
CVE-2016-8363CRITICAL
10.0
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Seri…Feb 13, 2017›
CVE-2019-5138CRITICAL
9.9
An exploitable command injection vulnerability exists in encrypted diagnostic script functionality o…Feb 25, 2020›
CVE-2024-9140CRITICAL
9.8
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical …Jan 3, 2025›
CVE-2023-28697CRITICAL
9.8
Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user…Apr 27, 2023›
CVE-2021-40390CRITICAL
9.8
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Se…Apr 14, 2022›
CVE-2021-32976CRITICAL
9.8
Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version …Apr 1, 2022›
CVE-2021-32974CRITICAL
9.8
Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware vers…Apr 1, 2022›
CVE-2021-46560CRITICAL
9.8
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device …Jan 26, 2022›
CVE-2021-38458CRITICAL
9.8
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 …Oct 12, 2021›
CVE-2021-38456CRITICAL
9.8
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3…Oct 12, 2021›
CVE-2020-28144CRITICAL
9.8
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series F…Feb 3, 2021›
CVE-2020-25196CRITICAL
9.8
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet …Dec 23, 2020›
CVE-2020-25153CRITICAL
9.8
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require …Dec 23, 2020›
CVE-2020-23639CRITICAL
9.8
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower …Nov 2, 2020›
CVE-2020-7007CRITICAL
9.8
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or…Mar 24, 2020›
CVE-2020-6991CRITICAL
9.8
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an att…Mar 24, 2020›
CVE-2020-6981CRITICAL
9.8
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system w…Mar 24, 2020›
CVE-2020-6995CRITICAL
9.8
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-6985CRITICAL
9.8
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-6989CRITICAL
9.8
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2019-9099CRITICAL
9.8
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-9096CRITICAL
9.8
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-9095CRITICAL
9.8
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2018-11425CRITICAL
9.8
Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 a…Jul 3, 2019›
CVE-2018-11422CRITICAL
9.8
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration p…Jul 3, 2019›
CVE-2018-11421CRITICAL
9.8
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring prot…Jul 3, 2019›
CVE-2018-11420CRITICAL
9.8
There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 1…Jul 3, 2019›
CVE-2018-11426CRITICAL
9.8
A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 …Jul 3, 2019›
CVE-2018-10698CRITICAL
9.8
An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET serv…Jun 7, 2019›
CVE-2019-6526CRITICAL
9.8
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A serie…Apr 15, 2019›
CVE-2019-6563CRITICAL
9.8
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to …Mar 5, 2019›
CVE-2019-6557CRITICAL
9.8
Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow re…Mar 5, 2019›
CVE-2019-6524CRITICAL
9.8
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication atte…Mar 5, 2019›
CVE-2018-18396CRITICAL
9.8
Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions versio…Oct 19, 2018›
CVE-2018-18395CRITICAL
9.8
Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version …Oct 19, 2018›
CVE-2018-18394CRITICAL
9.8
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Soft…Oct 19, 2018›
CVE-2018-18393CRITICAL
9.8
Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions ve…Oct 19, 2018›
CVE-2016-8717CRITICAL
9.8
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Acc…Apr 2, 2018›
CVE-2018-5455CRITICAL
9.8
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell …Mar 5, 2018›
CVE-2017-12729CRITICAL
9.8
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutraliza…Jan 18, 2018›
CVE-2017-13701CRITICAL
9.8
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensi…Nov 23, 2017›
CVE-2017-7915CRITICAL
9.8
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G31…May 29, 2017›
CVE-2017-7913CRITICAL
9.8
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 1…May 29, 2017›
CVE-2016-9369CRITICAL
9.8
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-9366CRITICAL
9.8
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-9361CRITICAL
9.8
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-9333CRITICAL
9.8
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does …Feb 13, 2017›
CVE-2016-5799CRITICAL
9.8
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not …Aug 24, 2016›
CVE-2016-5792CRITICAL
9.8
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary …Aug 8, 2016›
CVE-2016-5804CRITICAL
9.8
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before …Jul 15, 2016›
CVE-2016-4503CRITICAL
9.8
Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and conseque…Jul 12, 2016›
CVE-2024-9137CRITICAL
9.4
The affected product lacks an authentication check when sending commands to the server via the Moxa …Oct 14, 2024›
CVE-2021-25848CRITICAL
9.1
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort…May 10, 2021›
CVE-2021-25847CRITICAL
9.1
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort…May 10, 2021›
CVE-2019-6522CRITICAL
9.1
Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device mem…Mar 5, 2019›
CVE-2017-16727CRITICAL
9.1
A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort…Dec 22, 2017›
CVE-2016-8721CRITICAL
9.1
An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality…Apr 20, 2017›