CVE-2019-9096
Description
Moxa MGate MB3xxx series gateways with insufficient password requirements allow remote attackers to brute-force account passwords via the web application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Moxa MGate MB3xxx series gateways with insufficient password requirements allow remote attackers to brute-force account passwords via the web application.
Vulnerability
The vulnerability resides in the web application of Moxa MGate MB3170 and MB3270 devices before firmware version 4.1, MB3280 and MB3480 devices before version 3.1, MB3660 devices before version 2.3, and MB3180 devices before version 2.1. The application enforces insufficient password requirements, making accounts susceptible to brute-force attacks [1], [2].
Exploitation
An attacker with network access to the device's web interface can brute-force account passwords. No authentication is required to initiate the attack, and the low skill level needed makes exploitation straightforward. The predictable mechanism of token generation (CVE-2019-9102) may further assist an attacker in bypassing CSRF protection to perform password-guessing attempts [1].
Impact
Successful brute-forcing of an account password would grant an attacker authenticated access to the web application. This access could be leveraged to retrieve sensitive information (including usernames), modify configurations, or chain with other vulnerabilities like stack-based buffer overflows (CVE-2019-9099) to execute arbitrary code or cause denial of service [1], [2].
Mitigation
Moxa has released firmware updates to address the vulnerability: MB3170/MB3270 to version 4.1, MB3280/MB3480 to version 3.1, MB3660 to version 2.3, and MB3180 to version 2.1. Users should update their devices to these or later versions. As of the publication date, no workaround is documented, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog [1], [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Moxa/MGate MB3170description
- Range: <2.3
- Range: <3.1
- Range: <4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- www.moxa.com/en/support/support/security-advisory/mb3710-3180-3270-3280-3480-3660-vulnerabilitiesmitrex_refsource_CONFIRM
- www.us-cert.gov/ics/advisories/icsa-20-056-01mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.