Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Moxa — Vulnerabilities & Security Advisories 129

Browse all 129 CVE security advisories affecting Moxa. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Moxa specializes in industrial networking hardware, providing ruggedized switches, routers, and IoT gateways designed for harsh environments like manufacturing and transportation. The company’s product portfolio has accumulated 123 recorded Common Vulnerabilities and Exposures, reflecting the complexity of embedded systems in critical infrastructure. Historically, these security flaws predominantly involve remote code execution, buffer overflows, and improper access control mechanisms, which often allow attackers to gain unauthorized administrative privileges or disrupt network connectivity. While specific high-profile breaches directly attributed to Moxa hardware are less publicized compared to consumer electronics, the sheer volume of CVEs highlights persistent challenges in securing legacy industrial protocols and firmware updates. This pattern underscores the broader industry struggle to maintain robust cybersecurity hygiene in operational technology environments where stability often takes precedence over rapid patching cycles.

CVE ID Title CVSS Severity Published
CVE-2024-9404 Denial-of-Service Vulnerability — VPort 07-3 Series CWE-1287 7.5 High 2024-12-04
CVE-2024-4740 MXsecurity Use of Hard-coded Credentials — MXsecurity Series CWE-798 5.3 Medium 2024-10-18
CVE-2024-4739 MXsecurity License Generation Function Disclosure — MXsecurity Series CWE-749 5.3 Medium 2024-10-18
CVE-2024-9139 OS Command Injection in Restricted Command — EDR-8010 Series CWE-78 7.2 High 2024-10-14
CVE-2024-9137 Moxa Service Missing Authentication for Critical Function — EDR-8010 Series CWE-306 9.4 Critical 2024-10-14
CVE-2024-6787 MXview One Series vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition — MXview One Series CWE-367 5.3 Medium 2024-09-21
CVE-2024-6786 MXview One Series vulnerable to Path Traversal — MXview One Series CWE-24 6.5 Medium 2024-09-21
CVE-2024-6785 MXview One and MXview One Central Manager Series store cleartext credentials in a local file — MXview One Series CWE-313 5.5 Medium 2024-09-21
CVE-2024-4641 OnCell G3470A-LTE Series: Authenticated Format String Errors — OnCell G3150A-LTE Series CWE-134 6.3 Medium 2024-06-25
CVE-2024-4640 OnCell G3470A-LTE Series: Authenticated Command Injection via sendTestEmail — OnCell G3150A-LTE Series CWE-120 7.1 High 2024-06-25
CVE-2024-4639 OnCell G3470A-LTE Series: Authenticated Command Injection via webDelIPSec — OnCell G3150A-LTE Series CWE-77 7.1 High 2024-06-25
CVE-2024-4638 OnCell G3470A-LTE Series: Authenticated Command Injection via webUploadKey — OnCell G3470A-LTE Series CWE-77 7.1 High 2024-06-25
CVE-2024-3576 NPort 5100A Series Store XSS Vulnerability — NPort 5100A Series CWE-79 8.3 High 2024-05-06
CVE-2024-1220 NPort W2150A/W2250A Series Web Server Stack-based Buffer Overflow Vulnerability — NPort W2150A/W2250A Series CWE-121 8.2 High 2024-03-06
CVE-2024-0387 EDS-4000/G4000 Series IP Forwarding Vulnerability — EDS-4008 Series CWE-1188 6.5 Medium 2024-02-26
CVE-2023-6094 OnCell G3150A-LTE Series: Web Server Transmits Cleartext Credentials — OnCell G3150A-LTE Series CWE-319 5.3 Medium 2023-12-31
CVE-2023-6093 OnCell G3150A-LTE Series: Clickjacking Vulnerability — OnCell G3150A-LTE Series CWE-1021 5.3 Medium 2023-12-31
CVE-2023-5962 ioLogik E1200 Series: Weak Cryptographic Algorithm Vulnerability — ioLogik E1200 Series CWE-328 6.5 Medium 2023-12-23
CVE-2023-5961 ioLogik E1200 Series: Cross-Site Request Forgery (CSRF) Vulnerability — ioLogik E1200 Series CWE-352 8.8 High 2023-12-23
CVE-2023-5035 Cookie Without Secure Flag — PT-G503 Series CWE-614 3.1 Low 2023-11-02
CVE-2023-4217 Session cookies attribute not set properly — PT-G503 Series CWE-1004 3.1 Low 2023-11-02
CVE-2023-5627 Incorrect Implementation of Authentication Algorithm Vulnerability — NPort 6000 Series CWE-303 7.5 High 2023-11-01
CVE-2023-4452 Web Server Buffer Overflow Vulnerability — EDR-810 Series CWE-120 6.5 Medium 2023-11-01
CVE-2023-4929 NPort 5000 Series Firmware Improper Validation of Integrity Check Vulnerability — NPort 5000AI-M12 Series CWE-354 6.5 Medium 2023-10-03
CVE-2023-39983 MXsecurity Register Database Pollution — MXsecurity Series CWE-915 5.3 Medium 2023-09-02
CVE-2023-39982 MXsecurity Hardcoded Credential — MXsecurity Series CWE-321 7.5 High 2023-09-02
CVE-2023-39981 MXsecurity Device Information Disclosure — MXsecurity Series CWE-306 7.5 High 2023-09-02
CVE-2023-39980 MXsecurity Authenticated Information Disclosure Due to SQL Injection — MXsecurity Series CWE-89 7.1 High 2023-09-02
CVE-2023-39979 MXsecurity Authentication Bypass — MXsecurity Series CWE-334 9.8 Critical 2023-09-02
CVE-2023-4230 ioLogik 4000 Series: Server Banner Information Disclosure — ioLogik 4000 Series CWE-200 5.3 Medium 2023-08-24

This page lists every published CVE security advisory associated with Moxa. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.