← Back

Moxa

moxa

289 CVEs • 993 products

Products (993)

Click to collapse
Toggle
Mxview
mxview
Mxsecurity
mxsecurity
Softcms
softcms
Thingspro
thingspro

CVEs (289)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moxa
2Oncell G3001 Firmware
Oncell G3100v2 Firmware
May 6, 2026
Aug 24, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuratio...Show more
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuration file.Show less
1Moxa
2Oncell G3001 Firmware
Oncell G3100v2 Firmware
May 6, 2026
Aug 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force...Show more
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.Show less
1Moxa
1Softcms
May 6, 2026
Aug 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.
1Moxa
5Mgate Mb3170 Firmware
Mgate Mb3180 FirmwareMgate Mb3270 Firmware+2 more
May 6, 2026
Jul 15, 2016
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute...Show more
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.Show less
1Moxa
1Device Server Web Console 5232 N Firmware
May 6, 2026
Jul 12, 2016
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors related to reading a cookie parameter containing a UserId value.
1Moxa
2Pt 7728
Pt 7728 Firmware
May 6, 2026
Jun 19, 2016
N/A· v4
7.7 HIGH· v3
4.6 MEDIUM· v2
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy.
1Moxa
2Uc 7408 Lx Plus
Uc 7408 Lx Plus Firmware
May 6, 2026
Jun 1, 2016
N/A· v4
5.8 MEDIUM· v3
4.9 MEDIUM· v2
Moxa UC-7408 LX-Plus devices allow remote authenticated users to write to the firmware, and consequently render a device unusable, by leveraging root access.
1Moxa
5Miineport E1 4641 Firmware
Miineport E1 7080 FirmwareMiineport E2 1242 Firmware+2 more
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices wit...Show more
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allow remote attackers to obtain sensitive cleartext information by reading a configuration file.Show less
1Moxa
5Miineport E1 4641 Firmware
Miineport E1 7080 FirmwareMiineport E2 1242 Firmware+2 more
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices wit...Show more
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 have a blank default password, which allows remote attackers to obtain access via unspecified vectors.Show less
1Moxa
5Miineport E1 4641 Firmware
Miineport E1 7080 FirmwareMiineport E2 1242 Firmware+2 more
May 6, 2026
May 31, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmwar...Show more
Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.Show less
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting thes...Show more
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.Show less
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (memory consumption) by executing the ping function.
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
1Moxa
2Ioadmin Firmware
Iologik Firmware
May 6, 2026
Mar 4, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt data, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.
1Moxa
2Ioadmin Firmware
Iologik Firmware
May 6, 2026
Mar 4, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vect...Show more
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.Show less
1Moxa
1Oncell Central Manager
May 6, 2026
Dec 21, 2015
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.
1Moxa
1Oncell Central Manager
May 6, 2026
Dec 21, 2015
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGr...Show more
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.Show less
1Moxa
2Eds 405a Firmware
Eds 408a Firmware
May 6, 2026
Sep 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web s...Show more
Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web script or HTML via an unspecified field.Show less