Moxa Inc.

First CVE: May 22, 2023Active for: 3 years
74
CVEs Published
More CVEs Published than 66% of tracked CNAs
18.5
Avg CVEs / Year
More Avg CVEs / Year than 65% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 68% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Moxa Inc. as a CNA, 58.1% affect products that Moxa Inc. develops as a vendor.

58.1%
41.9%
Self-reported: 43Third-party: 31

Of all the CVEs published that affect products developed by Moxa Inc., 14.9% are self-published by Moxa Inc. as a CNA.

14.9%
85.1%
Self-published: 43Published by other CNAs: 246

Trends Over Time

The number and severity of CVEs published by Moxa Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2023
3 years ago
Most Recent CVE
Jun 16, 2026
38 days ago

Top CVEs

All CVEs published by Moxa Inc. as a CNA, regardless of affected vendor or product.

74 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HTT
Apr 27, 20268.734NONO
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web To
Oct 17, 20259.934NONO
A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validat
Jun 16, 20268.633NONO
The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s web
Dec 31, 20257.132NONO
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due
Jan 3, 20259.831NONO
NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affec
Aug 16, 20239.830NONO
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are inv
Jan 15, 20259.229NONO
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequentl
May 22, 20239.829NONO
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an
Jun 12, 20267.028NONO
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connect
Feb 5, 20266.828NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA74 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCriticalNone
Attack Vector
Local2 (2.7%)
Network68 (91.9%)
Unknown0 (0.0%)
Physical4 (5.4%)
Adjacent Network0 (0.0%)
Attack Complexity
Low70 (94.6%)
High4 (5.4%)
Unknown0 (0.0%)
User Interaction
None66 (89.2%)
Unknown0 (0.0%)
Required4 (5.4%)
Privileges Required
Low20 (27.0%)
High9 (12.2%)
None45 (60.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (74 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Moxa Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Moxa Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs