← All Advisories

CVE-2026-10829

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-10829

Key Details

CVECVE-2026-10829
CVSS Score / Version8.6 (High) / CVSS v4.0
Updated2026-06-17
Affected productsMoxa NPort W2150A-W4/W2250A-W4 Series and Moxa NPort W2150A/W2250A Series
Classified asCWE-121 (Stack-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MoxaNPort W2150A-W4/W2250A-W4 Series
MoxaNPort W2150A/W2250A Series
SubsystemsGeneral OT
SectorsMultiple

What to Know

A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input in the "Server location" parameter on the Basic settings page. An attacker could exploit this vulnerability by sending crafted input to the web service, resulting in memory corruption. Successful exploitation of this vulnerability could allow remote code execution on the target system with root privileges. (NVD)

What to Do

Monitor Moxa's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-10829
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-10829