Moxa serial device servers auth bypass flaw
CVE-2026-10831 affects Moxa CN2600 and NPort 6000 serial device servers, enabling remote denial of service and security policy bypass.
A vulnerability has been identified in Moxa serial device server products that allows attackers to bypass security policies and trigger remote denial of service conditions. The flaw, tracked as CVE-2026-10831, is described as an improper authorization vulnerability affecting the CN2600 Series running versions prior to 4.6.11 and NPort 6000 Series running versions prior to 2.3.9.
Moxa has released patches addressing this vulnerability in the affected product lines. Organizations running vulnerable versions of these serial device servers should apply the vendor-supplied updates to mitigate the risk of unauthorized access and service disruption.
Serial device servers are commonly deployed in industrial and critical infrastructure environments to enable network connectivity for serial devices, making this vulnerability relevant to operational technology networks where availability and access control are critical security requirements.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0763
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free