Moxa has disclosed multiple vulnerabilities in its NPort serial device server lines, including CVE-2026-10825, CVE-2026-10828, and CVE-2026-10829, affecting the NPort 6000-G2 Series, NPort W2150A-W4/W2250A-W4 Series, and older NPort W2150A/W2250A Series devices. The most severe issue, CVE-2026-10829, is a stack-based buffer overflow in the web interface's "Server location" parameter that can lead to memory corruption and potentially remote code execution with root privileges. Moxa also reported CVE-2026-10828, a format string flaw in the "alias" parameter that may expose sensitive memory and help bypass ASLR, and CVE-2026-10825, an improper JSON input validation flaw in the WebSocket API that can be exploited by a low-privileged authenticated attacker to cause denial of service and unexpected device reboots.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-17, the Canadian Centre for Cyber Security published advisory AV26-610 covering Moxa vulnerabilities CVE-2026-10825, CVE-2026-10828, and CVE-2026-10829 in several NPort serial device server lines. The Cyber Centre urged users and administrators to review Moxa's advisories and apply the necessary updates.
On 2026-06-17, CERT-FR published notice CERTFR-2026-AVI-0763 about a vulnerability in Moxa products. It said the flaw could let a remote attacker cause a denial-of-service condition and bypass security policy protections.
On 2026-06-16, CERT-FR published notice CERTFR-2026-AVI-0760 about multiple vulnerabilities in Moxa products. The notice said the flaws could allow arbitrary code execution, compromise confidentiality, and bypass security policy controls.
On 2026-06-16, Moxa published advisory MPSA-261910 covering CVE-2026-10828 and CVE-2026-10829 in NPort W2150A-W4/W2250A-W4 devices, with older W2150A/W2250A units also affected. The issues include a format string flaw and a stack-based buffer overflow that could enable memory disclosure, memory corruption, and potentially remote code execution with root privileges; Moxa provided firmware v1.5.1 for the W4 series and said phased-out older models should be replaced.
On 2026-06-16, Moxa published security advisory MPSA-268270 for CVE-2026-10825, an improper JSON input validation flaw in the WebSocket API affecting NPort 6000-G2 Series version 1.1.0 and earlier. Moxa said the issue could be exploited by a low-privileged authenticated attacker to cause denial of service or an unexpected reboot and advised updating to firmware v1.2.0 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecert.ssi.gouv.fr
Open sourcecert.ssi.gouv.fr
Open sourcecvefeed.io
Open sourcemoxa.com
Open sourcemoxa.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.