← Back

Moxa

moxa

289 CVEs • 993 products

Products (993)

Click to collapse
Toggle
Mxview
mxview
Mxsecurity
mxsecurity
Softcms
softcms
Thingspro
thingspro

CVEs (289)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moxa
4Nport Iaw5150a 12i/o Firmware
Nport Iaw5150a 6i/o FirmwareNport Iaw5250a 12i/o Firmware+1 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.
1Moxa
4Nport Iaw5150a 12i/o Firmware
Nport Iaw5150a 6i/o FirmwareNport Iaw5250a 12i/o Firmware+1 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.
1Moxa
6Mgate 5101 Pbm Mn T Firmware
Mgate 5101 Pbm Mn FirmwareMgate 5109 T Firmware+3 more
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service...Show more
Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.Show less
1Moxa
1Tn 5900 Firmware
Jun 17, 2026
Jan 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.
1Moxa
1Tn 5900 Firmware
Jun 17, 2026
Jan 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.
1Moxa
3Mgate Mb3180 Firmware
Mgate Mb3280 FirmwareMgate Mb3480 Firmware
Jun 17, 2026
Dec 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
1Moxa
1Mxview
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
1Moxa
1Mxview
Jun 17, 2026
Oct 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
1Moxa
1Mxview
Jun 17, 2026
Oct 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
1Moxa
1Mxview
Jun 17, 2026
Oct 12, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
1Moxa
1Mxview
Jun 17, 2026
Oct 12, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
1Moxa
12Oncell G3470a Lte Eu T Firmware
Oncell G3470a Lte Eu FirmwareTap 323 Eu Ct T Firmware+9 more
Jun 17, 2026
Sep 7, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TA...Show more
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.Show less
1Moxa
12Oncell G3470a Lte Eu T Firmware
Oncell G3470a Lte Eu FirmwareTap 323 Eu Ct T Firmware+9 more
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3...Show more
Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.Show less
1Moxa
1Mgate Mb3180 Firmware
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection,...Show more
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.Show less
1Moxa
1Mgate Mb3180 Firmware
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.
1Moxa
3Nport Ia5150a Firmware
Nport Ia5250a FirmwareNport Ia5450a Firmware
Jun 17, 2026
May 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration,...Show more
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.Show less
1Moxa
3Nport Ia5150a Firmware
Nport Ia5250a FirmwareNport Ia5450a Firmware
Jun 17, 2026
May 14, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.
1Moxa
3Nport Ia5150a Firmware
Nport Ia5250a FirmwareNport Ia5450a Firmware
Jun 17, 2026
May 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t s...Show more
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t set.Show less
1Moxa
3Nport Ia5150a Firmware
Nport Ia5250a FirmwareNport Ia5450a Firmware
Jun 17, 2026
May 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration changed.
1Moxa
16Vport 06ec 2v26m Firmware
Vport 06ec 2v36m Ct T FirmwareVport 06ec 2v36m Ct Firmware+13 more
Jun 17, 2026
May 10, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet.