← All Advisories

CVE-2026-10825

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-10825

Key Details

CVECVE-2026-10825
CVSS Score / Version7.1 (High) / CVSS v4.0
Updated2026-06-17
Affected productsMoxa NPort 6000-G2 Series
Classified asCWE-1287 (Improper Validation of Specified Type of Input)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MoxaNPort 6000-G2 Series
SubsystemsGeneral OT
SectorsMultiple

What to Know

A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device reboot. (NVD)

What to Do

Monitor Moxa's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-10825
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-10825