Project Subscriptions
No advisories yet.
Solution
Please refer to the security advisory: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-261910-cve-2026-10828,-cve-2026-10829-use-of-externally-controlled-format-string-and-stack-based-buffer-overflow-v
Workaround
No workaround given by the vendor.
Tue, 16 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections. | |
| First Time appeared |
Moxa
Moxa nport W2150a-w4 W2250a-w4 Series Moxa nport W2150a W2250a Series |
|
| Weaknesses | CWE-134 | |
| CPEs | cpe:2.3:a:moxa:nport_w2150a-w4_w2250a-w4_series:*:*:*:*:*:*:*:* cpe:2.3:a:moxa:nport_w2150a_w2250a_series:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Moxa
Moxa nport W2150a-w4 W2250a-w4 Series Moxa nport W2150a W2250a Series |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Moxa
Published:
Updated: 2026-06-16T12:20:06.556Z
Reserved: 2026-06-04T09:42:25.815Z
Link: CVE-2026-10828
Updated: 2026-06-16T12:20:00.512Z
Status : Awaiting Analysis
Published: 2026-06-16T12:16:24.920
Modified: 2026-06-16T15:26:04.250
Link: CVE-2026-10828
No data.
OpenCVE Enrichment
No data.