Vulnerabilidades en Moxa

129 resultados
Análisis Vexday

Com 119 CVEs catalogadas, o portfólio da Moxa apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem registros confirmados de exploração em produção até o momento. No entanto, a ausência de PoCs públicas conhecidas não elimina o risco: o tipo de falha mais recorrente é CWE-78 (OS Command Injection), categoria historicamente atrativa para atacantes em ambientes de tecnologia operacional e redes industriais. A CVE mais perigosa em evidência hoje é CVE-2022-40224, com EPSS de 0,6469 — valor que indica probabilidade relevante de exploração próxima e merece atenção prioritária nas esteiras de patch. As 17 vulnerabilidades de severidade crítica e as 8 CVEs surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo para equipes que operam equipamentos Moxa em ambientes críticos.

CVE-2025-6892HIGHAn Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authenticaEPSS 0.5%CVE-2024-9137HIGHMoxa Service Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-10829HIGHA stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerabiliEPSS 0.5%CVE-2025-9315MEDIUMUnauthenticated Device Registration Vulnerability in MXsecurity SeriesEPSS 0.5%CVE-2023-34217HIGHSecond Order Command-injection Vulnerability in the Certificate-delete FunctionEPSS 0.4%CVE-2023-4230MEDIUMioLogik 4000 Series: Server Banner Information DisclosureEPSS 0.4%CVE-2023-4452MEDIUMWeb Server Buffer Overflow VulnerabilityEPSS 0.4%CVE-2024-4639HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via webDelIPSecEPSS 0.4%CVE-2023-34214HIGHSecond Order Command-injection Vulnerability in the Certificate-generation FunctionEPSS 0.4%CVE-2026-15579HIGHAn out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length durEPSS 0.4%CVE-2023-39982HIGHMXsecurity Hardcoded CredentialEPSS 0.4%CVE-2024-4638HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via webUploadKeyEPSS 0.4%CVE-2025-2026HIGHThe NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a nullEPSS 0.4%CVE-2024-4640HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via sendTestEmailEPSS 0.4%CVE-2023-4204MEDIUMNPort IAW5000A-I/O Series Hardcoded Credential VulnerabilityEPSS 0.4%CVE-2024-3576HIGHNPort 5100A Series Store XSS VulnerabilityEPSS 0.4%CVE-2023-5961HIGHioLogik E1200 Series: Cross-Site Request Forgery (CSRF) VulnerabilityEPSS 0.4%CVE-2023-4229MEDIUMioLogik 4000 Series: Session Headers Not ImplementedEPSS 0.4%CVE-2026-3868HIGHAn improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper vaEPSS 0.4%CVE-2023-4227MEDIUMioLogik 4000 Series: Existence of an Unauthorized ServiceEPSS 0.4%