CVE-2026-10831
Description
Improper authorization on the command port of Moxa NPort devices allows remote attackers to disrupt serial communication via crafted break signal requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper authorization on the command port of Moxa NPort devices allows remote attackers to disrupt serial communication via crafted break signal requests.
Vulnerability
The vulnerability exists in Moxa NPort serial device servers. The command interface does not properly verify that a sender is associated with a valid data port session before processing break signal commands. This missing authorization (CWE-862) allows an attacker to send crafted break signal requests. Affected product series include NPort devices; specific versions are documented in Moxa security advisory MPSA-262370 [1].
Exploitation
An attacker with network access to the command port can send specially crafted requests containing break signal commands. No authentication is required (CVSS 4.0 vector indicates PR:N). The attacker does not need prior knowledge of active sessions. By sending the malicious break signal, the attacker disrupts ongoing serial communication for legitimate users.
Impact
Successful exploitation results in denial of service — the serial communication for an active user session is disrupted. This can cause temporary loss of serial device connectivity, affecting integrity (low) and availability (low) of the serial link. Confidentiality is not impacted per the CVSS vector [1].
Mitigation
Moxa has developed firmware updates for affected NPort product series. Users should apply the patches as provided in security advisory MPSA-262370 [1]. As the severity is medium, users may schedule the update during the next maintenance cycle. No workarounds are documented.
AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.