Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mobatek

First CVE: Nov 4, 2015Active for: 11 yearsTotal CVEs: 11
55.3
VTI Score
TOP TARGET

Mobatek develops MobaXterm, a widely deployed terminal-emulation and remote-access application that consolidates SSH, RDP, and X11 capabilities into a single client, giving vulnerabilities in this product an outsized reach across system-administration and development workflows. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and shows a moderate tendency toward public exploit availability, while recurring weakness classes center on improper access control, authentication bypasses, code injection, path traversal, and argument injection—exposures typical of an application that parses user input and interprets remote protocol responses. Defenders should treat MobaXterm updates with high priority given the product's privileged access context and the severity profile of its disclosures; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mobatek over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2015
10 years ago
Most Recent CVE
Mar 9, 2026
137 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-6805MEDIUM
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command.
Mar 20, 20175.333NOYES
CVE-2019-7690CRITICAL
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the us
May 13, 20199.832NONO
CVE-2017-15376CRITICAL
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.
Oct 16, 20179.831NONO
CVE-2019-16305HIGH
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the
Sep 14, 20198.829NONO
CVE-2019-13475HIGH
In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially cr
Jul 9, 20198.829NONO
CVE-2022-38337CRITICAL
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of
Dec 6, 20229.128NONO
CVE-2026-25866HIGH
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable
Mar 9, 20267.824NONO
CVE-2021-28847HIGH
MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in m
Jun 3, 20217.524NONO
CVE-2015-7244HIGH
The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which al
Nov 4, 20157.521NONO
CVE-2022-38336HIGH
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
Dec 6, 20228.120NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
18%
55%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (18.2%)
Network8 (72.7%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High1 (9.1%)
Unknown1 (9.1%)
User Interaction
None8 (72.7%)
Unknown1 (9.1%)
Required2 (18.2%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None8 (72.7%)
Unknown1 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mobatek.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mobatek — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mobatek's Products

View all 4 CNAs →

Top CWEs