Mobaxterm

Vendor:

First CVE: Nov 4, 2015 · Active for 10 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mobaxterm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2015
10 years ago
Most Recent CVE
Mar 9, 2026
138 days ago

CVE Severity & Scoring

Mobaxterm11 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local2 (18.2%)
Network8 (72.7%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High1 (9.1%)
Unknown1 (9.1%)
User Interaction
None8 (72.7%)
Unknown1 (9.1%)
Required2 (18.2%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None8 (72.7%)
Unknown1 (9.1%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command.
Mar 20, 20175.333NOYES
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the us
May 13, 20199.832NONO
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.
Oct 16, 20179.831NONO
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the
Sep 14, 20198.829NONO
In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially cr
Jul 9, 20198.829NONO
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of
Dec 6, 20229.128NONO
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable
Mar 9, 20267.824NONO
MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in m
Jun 3, 20217.524NONO
The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which al
Nov 4, 20157.521NONO
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
Dec 6, 20228.120NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Mobaxterm

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.415.37.8%01
12.118.86.7%00
11.139.14.7%00
10.419.83.8%00