VORANT. Threat Intelligence Sign in Get the full feed

Moxa NPort flaws enable RCE on industrial gateways

high vulnerability manufacturingenergyinfrastructure

Multiple vulnerabilities in Moxa NPort serial device servers allow remote code execution, data exposure, and policy bypass; patches available.

CERT-FR has disclosed multiple vulnerabilities affecting Moxa NPort serial device servers, which are widely deployed in industrial and critical infrastructure environments for serial-to-Ethernet connectivity. The flaws include a format string vulnerability (CVE-2026-10828), a stack-based buffer overflow (CVE-2026-10829), and an input validation weakness (CVE-2026-10825). Exploitation could allow an attacker to execute arbitrary code remotely, compromise data confidentiality, bypass security policies, or trigger denial-of-service conditions.

Affected products include NPort 6000-G2 Series prior to v1.2.0, NPort W2150A-W4/W2250A-W4 Series prior to v1.5.1, and NPort W2150A/W2250A Series v2.3 without the latest security patches. Moxa has released patches for all affected product lines. Given the deployment profile of these devices in operational technology environments and the severity of the vulnerabilities, affected organizations should prioritize patching, particularly in sectors relying on serial device connectivity for industrial control systems.

Mentioned in this report

Vulnerabilities CVE-2026-10825CVE-2026-10828CVE-2026-10829

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0760

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free