VYPR

serial device servers

by Moxa

CVEs (3)

  • CVE-2026-10825HigJun 16, 2026
    risk 0.46cvss epss

    A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device…

  • CVE-2025-15017HigDec 31, 2025
    risk 0.46cvss epss 0.00

    A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain…

  • CVE-2012-4577Aug 21, 2012
    risk 0.00cvss epss 0.04

    The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for the root account, which allows remote attackers to obtain administrative access via an SSH session.