MOXA NPort IAW5000A-I/O Series
Description
The MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not enforce strong passwords, allowing attackers to brute force or guess credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not enforce strong passwords, allowing attackers to brute force or guess credentials.
Vulnerability
The built-in web service on MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not enforce strong password requirements (CWE-521). This allows users to set weak passwords, making the device susceptible to credential guessing and brute force attacks.
Exploitation
An attacker with network access can remotely exploit this weakness by launching brute-force or dictionary attacks against the web service. Low skill level is required, as no authentication or user interaction is needed to initiate the attack.
Impact
Successful exploitation allows an attacker to gain unauthorized access to the device with the privileges of the compromised account. This could lead to session hijacking, data exposure, or further privilege escalation, as other vulnerabilities (e.g., improper privilege management) may be chained.
Mitigation
No fixed firmware version is explicitly mentioned in the available reference [1]. MOXA recommends upgrading to the latest firmware available for the NPort IAW5000A-I/O series. Until a patch is applied, enforce strong password policies through configuration and restrict network access to the web service.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=2.1+ 1 more
- (no CPE)range: <=2.1
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- us-cert.cisa.gov/ics/advisories/icsa-20-287-01mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.