Moxa NPort flaws enable RCE on industrial gateways
Multiple vulnerabilities in Moxa NPort serial device servers allow remote code execution, data exposure, and policy bypass; patches available.
CERT-FR has disclosed multiple vulnerabilities affecting Moxa NPort serial device servers, which are widely deployed in industrial and critical infrastructure environments for serial-to-Ethernet connectivity. The flaws include a format string vulnerability (CVE-2026-10828), a stack-based buffer overflow (CVE-2026-10829), and an input validation weakness (CVE-2026-10825). Exploitation could allow an attacker to execute arbitrary code remotely, compromise data confidentiality, bypass security policies, or trigger denial-of-service conditions.
Affected products include NPort 6000-G2 Series prior to v1.2.0, NPort W2150A-W4/W2250A-W4 Series prior to v1.5.1, and NPort W2150A/W2250A Series v2.3 without the latest security patches. Moxa has released patches for all affected product lines. Given the deployment profile of these devices in operational technology environments and the severity of the vulnerabilities, affected organizations should prioritize patching, particularly in sectors relying on serial device connectivity for industrial control systems.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0760
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free