VYPR
Vendor

Moxa

Products
618
CVEs
320
Across products
365
Status
Private

Products

618
View all 618 products →

Recent CVEs

320
View all 320 CVEs →
  • CVE-2017-14459CriApr 11, 2018
    risk 0.69cvss 10.0epss 0.13

    An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username…

  • CVE-2016-9361CriFeb 13, 2017
    risk 0.68cvss 9.8epss 0.20

    An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions…

  • CVE-2021-38454CriOct 12, 2021
    risk 0.66cvss 10.0epss 0.16

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2019-5138CriFeb 25, 2020
    risk 0.65cvss 9.9epss 0.05

    An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the…

  • CVE-2016-8363CriFeb 13, 2017
    risk 0.65cvss 10.0epss 0.02

    An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series,…

  • CVE-2025-6950CriOct 17, 2025
    risk 0.64cvss epss 0.01

    An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated…

  • CVE-2024-9140CriJan 3, 2025
    risk 0.64cvss 9.8epss 0.02

    Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code.…

  • CVE-2023-39979CriSep 2, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

  • CVE-2023-33236CriMay 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.

  • CVE-2023-28697CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.

  • CVE-2021-40390CriApr 14, 2022
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-32976CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to initiate a denial-of-service attack and execute arbitrary code.

  • CVE-2021-32974CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.

  • CVE-2021-46560CriJan 26, 2022
    risk 0.64cvss 9.8epss 0.04

    The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.

  • CVE-2021-4161CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.

  • CVE-2021-38458CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-38456CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.01

    A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords

  • CVE-2020-28144CriFeb 3, 2021
    risk 0.64cvss 9.8epss 0.03

    Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote…

  • CVE-2020-25196CriDec 23, 2020
    risk 0.64cvss 9.8epss 0.02

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.

  • CVE-2020-25153CriDec 23, 2020
    risk 0.64cvss 9.8epss 0.02

    The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.