Mobatek develops MobaXterm, a widely deployed terminal-emulation and remote-access application that consolidates SSH, RDP, and X11 capabilities into a single client, giving vulnerabilities in this product an outsized reach across system-administration and development workflows. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and shows a moderate tendency toward public exploit availability, while recurring weakness classes center on improper access control, authentication bypasses, code injection, path traversal, and argument injection—exposures typical of an application that parses user input and interprets remote protocol responses. Defenders should treat MobaXterm updates with high priority given the product's privileged access context and the severity profile of its disclosures; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mobatek over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6805MEDIUM Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command. | Mar 20, 2017 | 5.3 | 33 | NO | YES |
CVE-2019-7690CRITICAL In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the us | May 13, 2019 | 9.8 | 32 | NO | NO |
CVE-2017-15376CRITICAL The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23. | Oct 16, 2017 | 9.8 | 31 | NO | NO |
CVE-2019-16305HIGH In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the | Sep 14, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-13475HIGH In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially cr | Jul 9, 2019 | 8.8 | 29 | NO | NO |
CVE-2022-38337CRITICAL When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of | Dec 6, 2022 | 9.1 | 28 | NO | NO |
CVE-2026-25866HIGH MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable | Mar 9, 2026 | 7.8 | 24 | NO | NO |
CVE-2021-28847HIGH MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in m | Jun 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2015-7244HIGH The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which al | Nov 4, 2015 | 7.5 | 21 | NO | NO |
CVE-2022-38336HIGH An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication. | Dec 6, 2022 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mobatek.
Media articles that mention a CVE ID that affects a product developed by Mobatek — matched by CVE ID, not by vendor name.