VYPR

Vendor CVEs

Moxa

All CVEs

320 total · sorted by risk
  • CVE-2017-12127MedMay 14, 2018
    risk 0.29cvss 4.4epss 0.00

    A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.

  • CVE-2023-4229MedAug 24, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, potentially exposing users to security risks. This vulnerability may allow attackers to trick users into interacting with malicious content, leading to unintended actions…

  • CVE-2016-8720MedApr 13, 2017
    risk 0.28cvss 4.3epss 0.01

    An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be copied in to Location…

  • CVE-2016-9348LowFeb 13, 2017
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions…

  • CVE-2016-5812LowAug 24, 2016
    risk 0.21cvss 3.3epss 0.00

    Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuration file.

  • CVE-2023-5035LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plaintext over an HTTP session. The vulnerability may lead to…

  • CVE-2023-4217LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and…

  • CVE-2023-4228LowAug 24, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data…

  • CVE-2010-4742Feb 18, 2011
    risk 0.08cvss epss 0.56

    Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFileName property value.

  • CVE-2010-4741Feb 18, 2011
    risk 0.05cvss epss 0.28

    Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to execute arbitrary code via crafted data in a session on TCP port 54321.

  • CVE-2025-1680NonOct 23, 2025
    risk 0.00cvss epss 0.00

    An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests…

  • CVE-2015-6466Sep 11, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web script or HTML via an unspecified field.

  • CVE-2015-6465Sep 11, 2015
    risk 0.00cvss epss 0.03

    The GoAhead web server on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to cause a denial of service (reboot) via a crafted URL.

  • CVE-2015-6464Sep 11, 2015
    risk 0.00cvss epss 0.03

    The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.

  • CVE-2015-1000Jun 5, 2015
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3 allows remote attackers to execute arbitrary code via the StrRtspPath parameter.

  • CVE-2015-0986May 26, 2015
    risk 0.00cvss epss 0.02

    Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attackers to insert assembly-code lines via vectors involving a regkey (1) set or (2) get command.

  • CVE-2012-3039Aug 9, 2013
    risk 0.00cvss epss 0.01

    Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere.

  • CVE-2012-4712Feb 15, 2013
    risk 0.00cvss epss 0.02

    Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.

  • CVE-2012-4694Feb 15, 2013
    risk 0.00cvss epss 0.01

    Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a…

  • CVE-2012-4577Aug 21, 2012
    risk 0.00cvss epss 0.04

    The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for the root account, which allows remote attackers to obtain administrative access via an SSH session.

Page 7 of 7