Mobaxterm
Vendor:
First CVE: Nov 4, 2015 · Active for 10 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mobaxterm over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2015
10 years ago
Most Recent CVE
Mar 9, 2026
138 days ago
CVE Severity & Scoring
Mobaxterm11 CVEs
18%
55%
27%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (18.2%)
Network8 (72.7%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High1 (9.1%)
Unknown1 (9.1%)
User Interaction
None8 (72.7%)
Unknown1 (9.1%)
Required2 (18.2%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None8 (72.7%)
Unknown1 (9.1%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6805MEDIUM Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command. | Mar 20, 2017 | 5.3 | 33 | NO | YES |
CVE-2019-7690CRITICAL In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the us | May 13, 2019 | 9.8 | 32 | NO | NO |
CVE-2017-15376CRITICAL The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23. | Oct 16, 2017 | 9.8 | 31 | NO | NO |
CVE-2019-16305HIGH In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the | Sep 14, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-13475HIGH In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially cr | Jul 9, 2019 | 8.8 | 29 | NO | NO |
CVE-2022-38337CRITICAL When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of | Dec 6, 2022 | 9.1 | 28 | NO | NO |
CVE-2026-25866HIGH MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable | Mar 9, 2026 | 7.8 | 24 | NO | NO |
CVE-2021-28847HIGH MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in m | Jun 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2015-7244HIGH The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which al | Nov 4, 2015 | 7.5 | 21 | NO | NO |
CVE-2022-38336HIGH An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication. | Dec 6, 2022 | 8.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Mobaxterm
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4 | 1 | 5.3 | 7.8% | 0 | 1 |
| 12.1 | 1 | 8.8 | 6.7% | 0 | 0 |
| 11.1 | 3 | 9.1 | 4.7% | 0 | 0 |
| 10.4 | 1 | 9.8 | 3.8% | 0 | 0 |