VYPR

Vendor CVEs

Moxa

All CVEs

320 total · sorted by risk
  • CVE-2019-6559MedMar 5, 2019
    risk 0.42cvss 6.5epss 0.02

    Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch to crash.

  • CVE-2017-12124MedMay 14, 2018
    risk 0.42cvss 6.5epss 0.02

    An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in the web server crashing. An attacker can send a crafted URI to trigger this…

  • CVE-2018-5449MedMar 5, 2018
    risk 0.42cvss 6.5epss 0.00

    A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application does not check for a NULL value, allowing for an attacker to perform a denial of service attack.

  • CVE-2016-8362MedFeb 13, 2017
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series,…

  • CVE-2025-9315MedDec 10, 2025
    risk 0.41cvss epss 0.00

    An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determined Object Attributes, has been identified in the MXsecurity Series. An unauthenticated remote attacker can exploit this vulnerability by sending a specially…

  • CVE-2024-4641MedJun 25, 2024
    risk 0.41cvss 6.3epss 0.00

    OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.

  • CVE-2016-8350MedFeb 13, 2017
    risk 0.41cvss 6.3epss 0.01

    An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik…

  • CVE-2021-39278MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.01

    Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T…

  • CVE-2018-10692MedJun 7, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to steal the cookie very easily.

  • CVE-2016-5819MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.01

    Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary script code in the user’s browser within the trust…

  • CVE-2019-6565MedMar 5, 2019
    risk 0.40cvss 6.1epss 0.01

    Moxa IKS and EDS fails to properly validate user input, giving unauthenticated and authenticated attackers the ability to perform XSS attacks, which may be used to send a malicious script.

  • CVE-2016-8719MedApr 12, 2017
    risk 0.40cvss 6.1epss 0.01

    An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multiple parameters, can cause a malicious scripts to be executed by a victim.

  • CVE-2016-9371MedFeb 13, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions…

  • CVE-2016-8359MedFeb 13, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik…

  • CVE-2026-3867MedApr 27, 2026
    risk 0.39cvss epss 0.00

    An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the hashed password of the administrative account. Successful…

  • CVE-2020-27184MedMay 14, 2021
    risk 0.38cvss 5.9epss 0.00

    The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.

  • CVE-2016-4500MedJun 1, 2016
    risk 0.38cvss 5.8epss 0.01

    Moxa UC-7408 LX-Plus devices allow remote authenticated users to write to the firmware, and consequently render a device unusable, by leveraging root access.

  • CVE-2024-6785MedSep 21, 2024
    risk 0.36cvss 5.5epss 0.00

    The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

  • CVE-2017-7457MedApr 14, 2017
    risk 0.36cvss 5.0epss 0.02

    XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.

  • CVE-2016-9354MedFeb 13, 2017
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Moxa DACenter Versions 1.4 and older. A specially crafted project file may cause the program to crash because of Uncontrolled Resource Consumption.

  • CVE-2023-4204MedAug 16, 2023
    risk 0.35cvss 5.4epss 0.00

    NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presence of a hardcoded key, which could…

  • CVE-2022-41313MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this…

  • CVE-2022-41312MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this…

  • CVE-2022-41311MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this…

  • CVE-2022-40691MedFeb 7, 2023
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this…

  • CVE-2020-25192MedDec 23, 2020
    risk 0.35cvss 5.3epss 0.01

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authorization.

  • CVE-2020-12117MedMay 1, 2020
    risk 0.35cvss 5.3epss 0.01

    Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800. NOTE: Moxa Service is an unauthenticated service that runs upon a first-time installation but can be disabled…

  • CVE-2019-9103MedMar 11, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker can access sensitive information (e.g., conduct username disclosure attacks) on the built-in…

  • CVE-2019-9097MedMar 11, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A high rate of transit traffic may cause a low-memory condition and a denial of service.

  • CVE-2017-13702MedNov 17, 2017
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused.

  • CVE-2016-8725MedApr 13, 2017
    risk 0.35cvss 5.3epss 0.01

    An exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access point running firmware 1.1. Retrieving a specific URL without authentication can reveal sensitive information to an attacker.

  • CVE-2016-8724MedApr 13, 2017
    risk 0.35cvss 5.3epss 0.04

    An exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted TCP query will allow an attacker to retrieve potentially sensitive information.

  • CVE-2016-8722MedApr 13, 2017
    risk 0.35cvss 5.3epss 0.01

    An exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client. Retrieving a specific URL without authentication can reveal sensitive information to an attacker.

  • CVE-2016-9346MedFeb 13, 2017
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. Configuration data are stored in a file that is not encrypted.

  • CVE-2016-2283MedMar 4, 2016
    risk 0.35cvss 5.3epss 0.02

    Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt data, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.

  • CVE-2016-2282MedMar 4, 2016
    risk 0.35cvss 5.3epss 0.02

    Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.

  • CVE-2025-6894MedOct 17, 2025
    risk 0.34cvss epss 0.01

    An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping`…

  • CVE-2025-0193MedJan 15, 2025
    risk 0.34cvss epss 0.00

    A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can…

  • CVE-2024-4740MedOct 18, 2024
    risk 0.34cvss 5.3epss 0.00

    MXsecurity software versions v1.1.0 and prior are vulnerable because of the use of hard-coded credentials. This vulnerability could allow an attacker to tamper with sensitive data.

  • CVE-2024-4739MedOct 18, 2024
    risk 0.34cvss 5.3epss 0.00

    The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior vulnerable. By acquiring a valid authenticator, an attacker can pose as an authorized user and successfully access the resource.

  • CVE-2024-6787MedSep 21, 2024
    risk 0.34cvss 5.3epss 0.00

    This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could allow the attacker to execute malicious…

  • CVE-2023-6094MedDec 31, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic between the web browser and server may…

  • CVE-2023-6093MedDec 31, 2023
    risk 0.34cvss 5.3epss 0.00

    A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This…

  • CVE-2023-39983MedSep 2, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web…

  • CVE-2023-4230MedAug 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the…

  • CVE-2023-4227MedAug 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized…

  • CVE-2023-3336MedJul 5, 2023
    risk 0.34cvss 5.3epss 0.01

    TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.…

  • CVE-2025-1679MedOct 23, 2025
    risk 0.31cvss epss 0.00

    Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface.…

  • CVE-2019-10963MedOct 8, 2019
    risk 0.31cvss 4.3epss 0.07

    Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.

  • CVE-2017-13700MedNov 17, 2017
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.

Page 6 of 7