VYPR
Unrated severityNVD Advisory· Published Apr 1, 2022· Updated Apr 16, 2025

Moxa NPort IAW5000A-I/O Series Serial Device Server Stack-based Buffer Overflow

CVE-2021-32976

Description

Stack-based buffer overflows in Moxa NPort IAW5000A-I/O web server allow remote unauthenticated attackers to cause denial of service or execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflows in Moxa NPort IAW5000A-I/O web server allow remote unauthenticated attackers to cause denial of service or execute arbitrary code.

Vulnerability

Five stack-based buffer overflow vulnerabilities (CWE-121) exist in the built-in web server of Moxa NPort IAW5000A-I/O series wireless device servers running firmware Version 2.2 or earlier [1][2]. The affected product series is the NPort IAW5000A-I/O [1]. These overflows occur when the web server processes specially crafted network requests without proper bounds checking [2].

Exploitation

An attacker can exploit these vulnerabilities remotely over the network with low attack complexity and no required privileges or user interaction [2]. The attacker sends a crafted request to the web server, triggering a stack-based buffer overflow [2]. No authentication is needed, and the attack does not require any special network position beyond reachability of the device [2].

Impact

Successful exploitation can cause a denial-of-service condition (device crash) or allow arbitrary code execution with the privileges of the web server process [1][2]. The CVSS v3 base score is 9.8 (Critical) with the vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating complete compromise of confidentiality, integrity, and availability [2].

Mitigation

Moxa released a security advisory (MPSA-210501) on May 27, 2021, recommending users upgrade to a fixed firmware version [1]. Users should contact Moxa support for the latest firmware update [1]. No workarounds are documented [1]. CISA also advises applying the update [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.