securityonline.info 6/18/2026, 9:51:59 AM · external

Moxa NPort servers hit by critical root access bug CVE-2026-10829

Moxa NPort servers hit by critical root access bug CVE-2026-10829
CyberSIXT Evidence Panel
Primary Source moxa.com
CISA KEV Not in KEV
Patch Patch Status Unknown

MOXA has revealed two critical vulnerabilities in its NPort serial device servers, particularly affecting devices bridging serial equipment to Ethernet networks. The most severe vulnerability, CVE-2026-10829, involves a stack-based buffer overflow, allowing attackers with valid credentials to achieve root control through poor input validation. The second flaw, CVE-2026-10828, is a format string issue that can leak sensitive memory contents and facilitate further exploitation.

Both vulnerabilities can lead to serious security risks in industrial settings. Affected devices include NPort W2150A-W4 and W2250A-W4 Series running firmware version 1.5 or earlier, and patches have been released to mitigate these issues. Network security measures are advised until patches are applied.

View Primary Source Via securityonline.info

Article by CyberSIXT