# Moxa serial device servers auth bypass flaw

Published: 2026-06-17 · Severity: medium · Sectors: infrastructure, manufacturing, energy
Canonical: https://vorant.io/reports/8039e28c-6fdf-5b0d-8c86-9181e34d1632/moxa-serial-device-servers-auth-bypass-flaw

> CVE-2026-10831 affects Moxa CN2600 and NPort 6000 serial device servers, enabling remote denial of service and security policy bypass.

A vulnerability has been identified in Moxa serial device server products that allows attackers to bypass security policies and trigger remote denial of service conditions. The flaw, tracked as CVE-2026-10831, is described as an improper authorization vulnerability affecting the CN2600 Series running versions prior to 4.6.11 and NPort 6000 Series running versions prior to 2.3.9.

Moxa has released patches addressing this vulnerability in the affected product lines. Organizations running vulnerable versions of these serial device servers should apply the vendor-supplied updates to mitigate the risk of unauthorized access and service disruption.

Serial device servers are commonly deployed in industrial and critical infrastructure environments to enable network connectivity for serial devices, making this vulnerability relevant to operational technology networks where availability and access control are critical security requirements.

## Mentioned in this report

- Vulnerabilities: CVE-2026-10831

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0763

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8039e28c-6fdf-5b0d-8c86-9181e34d1632/moxa-serial-device-servers-auth-bypass-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
