AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Moxa
MO
Platform

Moxa

Industrial serial servers, Ethernet switches, cellular gateways, and Edge computing for IIoT environments.

https://www.moxa.com →
260
Total CVEs
0
Resources
59
CRIT
145
HIGH
44
MED
2
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
145 / 260
CVE-2010-4742HIGH

Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFileName property value.

Feb 18, 2011
10.0
CVE-2010-4741HIGH

Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to execute arbitrary code via crafted data in a session on TCP port 54321.

Feb 18, 2011
9.3
CVE-2021-39279HIGH

Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.

Sep 7, 2021
8.8
CVE-2020-25198HIGH

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s cookies.

Dec 23, 2020
8.8
CVE-2020-25194HIGH

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.

Dec 23, 2020
8.8
CVE-2019-9102HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.

Mar 11, 2020
8.8
CVE-2019-5162HIGH

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5153HIGH

An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5143HIGH

An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5141HIGH

An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5140HIGH

An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5136HIGH

An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2020-8858HIGH

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9552.

Feb 14, 2020
8.8
CVE-2018-11427HIGH

CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.

Jul 3, 2019
8.8
CVE-2018-10703HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_serverip" is susceptible to buffer overflow. By crafting a packet that contains a string of 480 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10702HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to command injection via shell metacharacters.

Jun 7, 2019
8.8
CVE-2018-10701HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to buffer overflow. By crafting a packet that contains a string of 162 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10699HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_privatePass" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10697HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10696HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters and forms/webSetMainRestart URIs.

Jun 7, 2019
8.8
CVE-2018-10695HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. However, the same functionality allows an attacker to execute commands on the device. The POST parameters "to1,to2,to3,to4" are all susceptible to buffer overflow. By crafting a packet that contains a string of 678 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10693HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to a buffer overflow. By crafting a packet that contains a string of 516 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2015-6458HIGH

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.

Mar 21, 2019
8.8
CVE-2015-6457HIGH

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.

Mar 21, 2019
8.8
CVE-2019-6561HIGH

Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.

Mar 5, 2019
8.8
CVE-2018-19660HIGH

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/webSettingProfileSecurity can result in running OS commands as the root user.

Dec 6, 2018
8.8
CVE-2018-19659HIGH

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/net_WebPingGetValue can result in running OS commands as the root user. This is similar to CVE-2017-12120.

Dec 6, 2018
8.8
CVE-2018-18392HIGH

Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
8.8
CVE-2018-18391HIGH

User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
8.8
CVE-2018-16282HIGH

A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.

Sep 20, 2018
8.8
CVE-2017-14434HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetmask0= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-14433HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetwork0= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-14432HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the openvpnServer0_tmp= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12126HIGH

An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forgery. An attacker can create malicious HTML to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12125HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the CN= parm in the "/goform/net_WebCSRGen" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12123HIGH

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.

May 14, 2018
8.8
CVE-2017-12121HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the rsakey\_name= parm in the "/goform/WebRSAKEYGen" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12120HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation, resulting in a root shell. An attacker can inject OS commands into the ip= parm in the "/goform/net_WebPingGetValue" URI to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-7917HIGH

A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.

May 29, 2017
8.8
CVE-2016-8718HIGH

An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.

Apr 12, 2017
8.8
CVE-2016-9365HIGH

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Requests are not verified to be intentionally submitted by the proper user (CROSS-SITE REQUEST FORGERY).

Feb 13, 2017
8.8
CVE-2016-5793HIGH

Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.

Sep 24, 2016
8.8
CVE-2016-2285HIGH

Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.

May 31, 2016
8.8
CVE-2015-6464HIGH

The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.

Sep 11, 2015
8.5
CVE-2015-6481HIGH

The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.

Dec 21, 2015
8.3
CVE-2015-6480HIGH

The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.

Dec 21, 2015
8.3
CVE-2024-1220HIGH

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.

Mar 6, 2024
8.2
CVE-2022-2044HIGH

MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite values in memory, causing a denial-of-service condition or potentially bricking the device.

Aug 31, 2022
8.2
CVE-2018-10694HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wireless connection to set up the device can allow an attacker to sniff the traffic passing between the user's computer and the device. This can allow an attacker to steal the credentials passing over the HTTP connection as well as TELNET traffic. Also an attacker can MITM the response and infect a user's computer very easily as well.

Jun 7, 2019
8.1
CVE-2018-10690HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allows an attacker to sniff the traffic easily and allows an attacker to compromise sensitive data such as credentials.

Jun 7, 2019
8.1
CVE-2016-8712HIGH

An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the web application has been idle for 300 seconds.

Apr 13, 2017
8.1
CVE-2016-8379HIGH

An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12. Users are restricted to using short passwords.

Feb 13, 2017
8.1
CVE-2016-8372HIGH

An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12. A password is transmitted in a format that is not sufficiently secure.

Feb 13, 2017
8.1
CVE-2016-8360HIGH

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and possibly cause a denial of service or the execution of arbitrary code.

Feb 13, 2017
8.1
CVE-2017-12129HIGH

An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypted passwords and could brute force them.

May 14, 2018
8.0
CVE-2022-48626HIGH

In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure could be accessed after it was freed in moxart_remove(), so fix this by saving the base register of the device and using it instead of the pointer dereference.

Feb 26, 2024
7.8
CVE-2022-3088HIGH

UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.

Nov 28, 2022
7.8
CVE-2020-13537HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality and among them the mosquitto executable is also run.

Nov 5, 2020
7.8
CVE-2020-13536HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality.

Nov 5, 2020
7.8
CVE-2017-14030HIGH

An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.

Jan 12, 2018
7.8
CVE-2016-9356HIGH

An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue.

Feb 13, 2017
7.8
CVE-2016-4514HIGH

Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy.

Jun 19, 2016
7.7
CVE-2023-1257HIGH

An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.

Mar 7, 2023
7.6
CVE-2012-4694HIGH

Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.

Feb 15, 2013
7.6
CVE-2024-9404HIGH

This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If exposed to public networks, the vulnerability poses a significant remote threat, potentially allowing attackers to shut down affected systems.

Dec 4, 2024
7.5
CVE-2022-40693HIGH

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

Feb 7, 2023
7.5
CVE-2022-40224HIGH

A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

Feb 7, 2023
7.5
CVE-2022-2043HIGH

MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unresponsive.

Aug 31, 2022
7.5
CVE-2021-40392HIGH

An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.

Apr 14, 2022
7.5
CVE-2021-32970HIGH

Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.

Apr 1, 2022
7.5
CVE-2021-32968HIGH

Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.

Apr 1, 2022
7.5
CVE-2021-46082HIGH

Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.

Feb 18, 2022
7.5
CVE-2021-46559HIGH

The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.

Jan 26, 2022
7.5
CVE-2021-38460HIGH

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Oct 12, 2021
7.5
CVE-2021-38452HIGH

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Oct 12, 2021
7.5
CVE-2021-33824HIGH

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

Jun 18, 2021
7.5
CVE-2021-33823HIGH

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.

Jun 18, 2021
7.5
CVE-2020-27185HIGH

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

May 14, 2021
7.5
CVE-2021-25849HIGH

An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet.

May 10, 2021
7.5
CVE-2021-25846HIGH

Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a negative number passed to the memcpy function via a crafted lldp packet.

May 10, 2021
7.5
CVE-2021-25845HIGH

Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a NULL pointer dereference via a crafted lldp packet.

May 10, 2021
7.5
CVE-2020-25190HIGH

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.

Dec 23, 2020
7.5
CVE-2020-7001HIGH

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

Mar 24, 2020
7.5
CVE-2020-6997HIGH

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.

Mar 24, 2020
7.5
CVE-2020-6979HIGH

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered.

Mar 24, 2020
7.5
CVE-2020-6993HIGH

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, an attacker can gain access to sensitive information from the web service without authorization.

Mar 24, 2020
7.5
CVE-2020-6987HIGH

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

Mar 24, 2020
7.5
CVE-2020-6983HIGH

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data can be recovered.

Mar 24, 2020
7.5
CVE-2020-7003HIGH

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

Mar 24, 2020
7.5
CVE-2019-18242HIGH

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to fail.

Mar 24, 2020
7.5
CVE-2019-9104HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.

Mar 11, 2020
7.5
CVE-2019-9101HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.

Mar 11, 2020
7.5
CVE-2019-9098HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An Integer overflow in the built-in web server allows remote attackers to initiate DoS.

Mar 11, 2020
7.5
CVE-2019-18238HIGH

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.

Feb 26, 2020
7.5
CVE-2019-5148HIGH

An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.

Feb 25, 2020
7.5
CVE-2019-5137HIGH

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

Feb 25, 2020
7.5
CVE-2019-19707HIGH

On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.

Dec 11, 2019
7.5
CVE-2018-11424HIGH

There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11425.

Jul 3, 2019
7.5
CVE-2018-11423HIGH

There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, different vulnerability than CVE-2018-11420.

Jul 3, 2019
7.5
CVE-2018-10691HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.

Jun 7, 2019
7.5
CVE-2019-6520HIGH

Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.

Mar 5, 2019
7.5
CVE-2019-6518HIGH

Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

Mar 5, 2019
7.5
CVE-2018-18390HIGH

User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
7.5
CVE-2018-10632HIGH

In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.

Jul 24, 2018
7.5
CVE-2017-14439HIGH

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4001/tcp to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14438HIGH

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14437HIGH

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_LOG.ini" without a cookie header to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14436HIGH

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG2.ini" without a cookie header to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14435HIGH

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG.ini" without a cookie header to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-12128HIGH

An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause information disclosure. An attacker can send a crafted TCP packet to trigger this vulnerability.

May 14, 2018
7.5
CVE-2018-7506HIGH

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

Apr 6, 2018
7.5
CVE-2018-5453HIGH

An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.

Mar 5, 2018
7.5
CVE-2017-13699HIGH

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POST parameter. An attacker could reverse the password encryption algorithm to retrieve it.

Nov 23, 2017
7.5
CVE-2017-13698HIGH

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract public and private keys from the firmware image available on the MOXA website and could use them against a production switch that has the default keys embedded.

Nov 23, 2017
7.5
CVE-2017-13703HIGH

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.

Nov 17, 2017
7.5
CVE-2017-16719HIGH

An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to inject packets that could potentially disrupt the availability of the device.

Nov 16, 2017
7.5
CVE-2017-16715HIGH

An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exploit a flaw in the handling of Ethernet frame padding that may allow for information exposure.

Nov 16, 2017
7.5
CVE-2017-14028HIGH

A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exhaust memory resources by sending a large amount of TCP SYN packets.

Nov 16, 2017
7.5
CVE-2017-7456HIGH

Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.

Apr 14, 2017
7.5
CVE-2017-7455HIGH

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

Apr 14, 2017
7.5
CVE-2016-8727HIGH

An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authentication can reveal sensitive configuration and system information to an attacker.

Apr 13, 2017
7.5
CVE-2016-8726HIGH

An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with a blank line in the header will cause a segmentation fault in the web server.

Apr 13, 2017
7.5
CVE-2016-8723HIGH

An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.

Apr 13, 2017
7.5
CVE-2016-8716HIGH

An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.

Apr 12, 2017
7.5
CVE-2016-9367HIGH

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. The amount of resources requested by a malicious actor is not restricted, leading to a denial-of-service caused by resource exhaustion.

Feb 13, 2017
7.5
CVE-2016-9344HIGH

An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.

Feb 13, 2017
7.5
CVE-2016-9332HIGH

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide unexpected values and cause the program to crash or excessive consumption of resources could result in a denial-of-service condition.

Feb 13, 2017
7.5
CVE-2016-8346HIGH

An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).

Feb 13, 2017
7.5
CVE-2016-2295HIGH

Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allow remote attackers to obtain sensitive cleartext information by reading a configuration file.

May 31, 2016
7.5
CVE-2016-2286HIGH

Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 have a blank default password, which allows remote attackers to obtain access via unspecified vectors.

May 31, 2016
7.5
CVE-2016-0879HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.

May 31, 2016
7.5
CVE-2016-0878HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.

May 31, 2016
7.5
CVE-2016-0877HIGH

Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (memory consumption) by executing the ping function.

May 31, 2016
7.5
CVE-2016-0876HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.

May 31, 2016
7.5
CVE-2016-0875HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.

May 31, 2016
7.5
CVE-2015-0986HIGH

Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attackers to insert assembly-code lines via vectors involving a regkey (1) set or (2) get command.

May 26, 2015
7.5
CVE-2022-27048HIGH

A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.

Apr 15, 2022
7.4
CVE-2016-9363HIGH

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Buffer overflow vulnerability may allow an unauthenticated attacker to remotely execute arbitrary code.

Feb 13, 2017
7.3
CVE-2024-9138HIGH

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.

Jan 3, 2025
7.2
CVE-2019-5165HIGH

An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

Feb 25, 2020
7.2
CVE-2019-5142HIGH

An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.

Feb 25, 2020
7.2
CVE-2019-10969HIGH

Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.

Oct 8, 2019
7.2
CVE-2017-5170HIGH

An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. To exploit this vulnerability, an attacker could rename a malicious DLL to meet the criteria of the application, and the application would not verify that the DLL is correct. The attacker needs to have administrative access to the default install location in order to plant the insecure DLL. Once loaded by the application, the DLL could run malicious code at the privilege level of the application.

Jan 18, 2018
7.2
CVE-2019-5139HIGH

An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

Feb 25, 2020
7.1
CVE-2012-3039HIGH

Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere.

Aug 9, 2013
7.1
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2010-4742HIGH
10.0
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa …Feb 18, 2011›
CVE-2010-4741HIGH
9.3
Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Mana…Feb 18, 2011›
CVE-2021-39279HIGH
8.8
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects W…Sep 7, 2021›
CVE-2020-25198HIGH
8.8
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly im…Dec 23, 2020›
CVE-2020-25194HIGH
8.8
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privi…Dec 23, 2020›
CVE-2019-9102HIGH
8.8
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-5162HIGH
8.8
An exploitable improper access control vulnerability exists in the iw_webs account settings function…Feb 25, 2020›
CVE-2019-5153HIGH
8.8
An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing funct…Feb 25, 2020›
CVE-2019-5143HIGH
8.8
An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of …Feb 25, 2020›
CVE-2019-5141HIGH
8.8
An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3…Feb 25, 2020›
CVE-2019-5140HIGH
8.8
An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-31…Feb 25, 2020›
CVE-2019-5136HIGH
8.8
An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa…Feb 25, 2020›
CVE-2020-8858HIGH
8.8
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mo…Feb 14, 2020›
CVE-2018-11427HIGH
8.8
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 1…Jul 3, 2019›
CVE-2018-10703HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ…Jun 7, 2019›
CVE-2018-10702HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ…Jun 7, 2019›
CVE-2018-10701HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ…Jun 7, 2019›
CVE-2018-10699HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload fu…Jun 7, 2019›
CVE-2018-10697HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality…Jun 7, 2019›
CVE-2018-10696HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow …Jun 7, 2019›
CVE-2018-10695HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an ad…Jun 7, 2019›
CVE-2018-10693HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an adm…Jun 7, 2019›
CVE-2015-6458HIGH
8.8
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow rem…Mar 21, 2019›
CVE-2015-6457HIGH
8.8
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow rem…Mar 21, 2019›
CVE-2019-6561HIGH
8.8
Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the executio…Mar 5, 2019›
CVE-2018-19660HIGH
8.8
An exploitable authenticated command-injection vulnerability exists in the web server functionality …Dec 6, 2018›
CVE-2018-19659HIGH
8.8
An exploitable authenticated command-injection vulnerability exists in the web server functionality …Dec 6, 2018›
CVE-2018-18392HIGH
8.8
Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management …Oct 19, 2018›
CVE-2018-18391HIGH
8.8
User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions ve…Oct 19, 2018›
CVE-2018-16282HIGH
8.8
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 1804101…Sep 20, 2018›
CVE-2017-14434HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14433HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14432HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12126HIGH
8.8
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Mo…May 14, 2018›
CVE-2017-12125HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12123HIGH
8.8
An exploitable clear text transmission of password vulnerability exists in the web server and telnet…May 14, 2018›
CVE-2017-12121HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12120HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-7917HIGH
8.8
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 150821…May 29, 2017›
CVE-2016-8718HIGH
8.8
An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality …Apr 12, 2017›
CVE-2016-9365HIGH
8.8
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-5793HIGH
8.8
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local user…Sep 24, 2016›
CVE-2016-2285HIGH
8.8
Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.…May 31, 2016›
CVE-2015-6464HIGH
8.5
The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 all…Sep 11, 2015›
CVE-2015-6481HIGH
8.3
The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a ha…Dec 21, 2015›
CVE-2015-6480HIGH
8.3
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authenti…Dec 21, 2015›
CVE-2024-1220HIGH
8.2
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware…Mar 6, 2024›
CVE-2022-2044HIGH
8.2
MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an at…Aug 31, 2022›
CVE-2018-10694HIGH
8.1
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that i…Jun 7, 2019›
CVE-2018-10690HIGH
8.1
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thu…Jun 7, 2019›
CVE-2016-8712HIGH
8.1
An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-313…Apr 13, 2017›
CVE-2016-8379HIGH
8.1
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmw…Feb 13, 2017›
CVE-2016-8372HIGH
8.1
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmw…Feb 13, 2017›
CVE-2016-8360HIGH
8.1
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL reque…Feb 13, 2017›
CVE-2017-12129HIGH
8.0
An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality …May 14, 2018›
CVE-2022-48626HIGH
7.8
In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after…Feb 26, 2024›
CVE-2022-3088HIGH
7.8
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-…Nov 28, 2022›
CVE-2020-13537HIGH
7.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa…Nov 5, 2020›
CVE-2020-13536HIGH
7.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa…Nov 5, 2020›
CVE-2017-14030HIGH
7.8
An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerab…Jan 12, 2018›
CVE-2016-9356HIGH
7.8
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an …Feb 13, 2017›
CVE-2016-4514HIGH
7.7
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the…Jun 19, 2016›
CVE-2023-1257HIGH
7.6
An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of th…Mar 7, 2023›
CVE-2012-4694HIGH
7.6
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for…Feb 15, 2013›
CVE-2024-9404HIGH
7.5
This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd …Dec 4, 2024›
CVE-2022-40693HIGH
7.5
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 …Feb 7, 2023›
CVE-2022-40224HIGH
7.5
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Ind…Feb 7, 2023›
CVE-2022-2043HIGH
7.5
MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the d…Aug 31, 2022›
CVE-2021-40392HIGH
7.5
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView S…Apr 14, 2022›
CVE-2021-32970HIGH
7.5
Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series f…Apr 1, 2022›
CVE-2021-32968HIGH
7.5
Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2…Apr 1, 2022›
CVE-2021-46082HIGH
7.5
Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2…Feb 18, 2022›
CVE-2021-46559HIGH
7.5
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to def…Jan 26, 2022›
CVE-2021-38460HIGH
7.5
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 …Oct 12, 2021›
CVE-2021-38452HIGH
7.5
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 …Oct 12, 2021›
CVE-2021-33824HIGH
7.5
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttpt…Jun 18, 2021›
CVE-2021-33823HIGH
7.5
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge …Jun 18, 2021›
CVE-2020-27185HIGH
7.5
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devi…May 14, 2021›
CVE-2021-25849HIGH
7.5
An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, ver…May 10, 2021›
CVE-2021-25846HIGH
7.5
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series…May 10, 2021›
CVE-2021-25845HIGH
7.5
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series…May 10, 2021›
CVE-2020-25190HIGH
7.5
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmi…Dec 23, 2020›
CVE-2020-7001HIGH
7.5
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptograp…Mar 24, 2020›
CVE-2020-6997HIGH
7.5
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over s…Mar 24, 2020›
CVE-2020-6979HIGH
7.5
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryp…Mar 24, 2020›
CVE-2020-6993HIGH
7.5
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-6987HIGH
7.5
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-6983HIGH
7.5
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-7003HIGH
7.5
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Vers…Mar 24, 2020›
CVE-2019-18242HIGH
7.5
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Vers…Mar 24, 2020›
CVE-2019-9104HIGH
7.5
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-9101HIGH
7.5
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-9098HIGH
7.5
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-18238HIGH
7.5
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Vers…Feb 26, 2020›
CVE-2019-5148HIGH
7.5
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-…Feb 25, 2020›
CVE-2019-5137HIGH
7.5
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption …Feb 25, 2020›
CVE-2019-19707HIGH
7.5
On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service c…Dec 11, 2019›
CVE-2018-11424HIGH
7.5
There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 1…Jul 3, 2019›
CVE-2018-11423HIGH
7.5
There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 1710…Jul 3, 2019›
CVE-2018-10691HIGH
7.5
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can down…Jun 7, 2019›
CVE-2019-6520HIGH
7.5
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user…Mar 5, 2019›
CVE-2019-6518HIGH
7.5
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by some…Mar 5, 2019›
CVE-2018-18390HIGH
7.5
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1…Oct 19, 2018›
CVE-2018-10632HIGH
7.5
In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources re…Jul 24, 2018›
CVE-2017-14439HIGH
7.5
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-…May 14, 2018›
CVE-2017-14438HIGH
7.5
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-…May 14, 2018›
CVE-2017-14437HIGH
7.5
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14436HIGH
7.5
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14435HIGH
7.5
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12128HIGH
7.5
An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa…May 14, 2018›
CVE-2018-7506HIGH
7.5
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and acces…Apr 6, 2018›
CVE-2018-5453HIGH
7.5
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSP…Mar 5, 2018›
CVE-2017-13699HIGH
7.5
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method…Nov 23, 2017›
CVE-2017-13698HIGH
7.5
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract publ…Nov 23, 2017›
CVE-2017-13703HIGH
7.5
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.Nov 17, 2017›
CVE-2017-16719HIGH
7.5
An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110…Nov 16, 2017›
CVE-2017-16715HIGH
7.5
An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4,…Nov 16, 2017›
CVE-2017-14028HIGH
7.5
A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, N…Nov 16, 2017›
CVE-2017-7456HIGH
7.5
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk pay…Apr 14, 2017›
CVE-2017-7455HIGH
7.5
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.Apr 14, 2017›
CVE-2016-8727HIGH
7.5
An exploitable information disclosure vulnerability exists in the Web Application functionality of M…Apr 13, 2017›
CVE-2016-8726HIGH
7.5
An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runSc…Apr 13, 2017›
CVE-2016-8723HIGH
7.5
An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131…Apr 13, 2017›
CVE-2016-8716HIGH
7.5
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functi…Apr 12, 2017›
CVE-2016-9367HIGH
7.5
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-9344HIGH
7.5
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3…Feb 13, 2017›
CVE-2016-9332HIGH
7.5
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does n…Feb 13, 2017›
CVE-2016-8346HIGH
7.5
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform re…Feb 13, 2017›
CVE-2016-2295HIGH
7.5
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with f…May 31, 2016›
CVE-2016-2286HIGH
7.5
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with f…May 31, 2016›
CVE-2016-0879HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log file…May 31, 2016›
CVE-2016-0878HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of servic…May 31, 2016›
CVE-2016-0877HIGH
7.5
Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a …May 31, 2016›
CVE-2016-0876HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passw…May 31, 2016›
CVE-2016-0875HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and l…May 31, 2016›
CVE-2015-0986HIGH
7.5
Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attacke…May 26, 2015›
CVE-2022-27048HIGH
7.4
A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-m…Apr 15, 2022›
CVE-2016-9363HIGH
7.3
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2024-9138HIGH
7.2
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-seve…Jan 3, 2025›
CVE-2019-5165HIGH
7.2
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK…Feb 25, 2020›
CVE-2019-5142HIGH
7.2
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-…Feb 25, 2020›
CVE-2019-10969HIGH
7.2
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature…Oct 8, 2019›
CVE-2017-5170HIGH
7.2
An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.3…Jan 18, 2018›
CVE-2019-5139HIGH
7.1
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the …Feb 25, 2020›
CVE-2012-3039HIGH
7.1
Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a suf…Aug 9, 2013›