logo

Moxa Patches NPort Flaws: Root RCE and Format String Bugs (CVE-2026-10829)

ID: fac67874-679b-54f9-aadf-486b010661e8

STIX ID: report--fac67874-679b-54f9-aadf-486b010661e8

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Do Son

...
...

Moxa has disclosed two web-service vulnerabilities in NPort W2150A-W4 and W2250A-W4 series (firmware v1.5 or earlier): CVE-2026-10829 is a CWE-121 stack-based buffer overflow (CVSS 8.6) in the "Server location" parameter that can yield root RCE for authenticated users, and CVE-2026-10828 is a format-string flaw (CVSS 6.9) in the "alias" parameter that can leak memory and help bypass ASLR; Moxa released firmware patch v1.5.1 and administrators are advised to apply patches, restrict web access, and segment networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.