Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86325

Quick assessment

Affected
Moxa MGate MB3170 Series
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

协议网关的账户管理接口中存在基于栈的缓冲区溢出漏洞。该漏洞是由于在处理账户管理请求时,对 参数的长度验证不足所致。攻击者如果以只读用户身份认证到 Web 管理界面,即可提交一个特别构造的、超出内部栈缓冲区大小的账户名,从而导致程序执行流被破坏。成功利用此漏洞可能使攻击者能够从设备内存中读取敏感信息(包括凭据),修改任意内存内容,并破坏设备的可用性。

CVSS 9.4 · Critical EPSS 0.34% · P25

Affected Version Matrix 2

VendorProduct Version RangeStatus
Moxa MGate MB3170 Series 1.0≤ 4.7 affected
Moxa MGate MB3270 Series 1.0≤ 4.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86325

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Moxa MGate MB3170 Series 1.0 ~ 4.7 -
Moxa MGate MB3270 Series 1.0 ~ 4.7 -

II. Public POCs for CVE-2026-86325

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86325

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-86325 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86325

No comments yet


Leave a comment