Moxa Inc. is a prominent provider of industrial networking and automation equipment, spanning a broad portfolio of wireless access points, industrial routers, and embedded devices deployed across manufacturing, utilities, and critical infrastructure environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical-severity disclosures, reflecting the memory-safety and input-validation demands of embedded systems that often operate in safety-critical or network-critical contexts. The exposure concentrates in flagship products such as the AWK-3131A wireless access point and the EDR-810 industrial router, and recurs through weakness classes including OS command injection, exposure of sensitive information, cleartext transmission of credentials, and buffer-overflow conditions that are endemic to industrial firmware and edge-device codebases. Defenders should prioritize inventory of Moxa devices in operational technology networks and treat firmware updates as urgent; internet-facing instances warrant particular attention given the vendor's placement in critical infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moxa Inc. over time
Of all the CVEs published by Moxa Inc. as a CNA, 58.1% affect products that Moxa Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Moxa Inc., 14.9% are self-published by Moxa Inc. as a CNA.
Signals from CVEs in this vendor scope (289 CVEs).
289 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4742HIGH Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFil | Feb 18, 2011 | 10.0 | 77 | NO | YES |
CVE-2010-4741HIGH Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to execute arbitrary code via crafted data in a s | Feb 18, 2011 | 9.3 | 63 | NO | YES |
CVE-2022-40224HIGH A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to | Feb 7, 2023 | 7.5 | 59 | NO | NO |
CVE-2017-7456HIGH Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials. | Apr 14, 2017 | 7.5 | 52 | NO | YES |
CVE-2017-14459CRITICAL An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/clie | Apr 11, 2018 | 9.8 | 48 | NO | YES |
CVE-2016-9361CRITICAL An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions | Feb 13, 2017 | 9.8 | 47 | NO | YES |
CVE-2017-12128HIGH An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause informati | May 14, 2018 | 7.5 | 44 | NO | NO |
CVE-2017-7455HIGH Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control. | Apr 14, 2017 | 7.5 | 44 | NO | YES |
CVE-2018-19660HIGH An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A special | Dec 6, 2018 | 8.8 | 42 | NO | NO |
CVE-2018-10700MEDIUM An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows | Jun 7, 2019 | 6.1 | 40 | NO | NO |
Signals from CVEs in this vendor scope (289 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moxa Inc..
Media articles that mention a CVE ID that affects a product developed by Moxa Inc. — matched by CVE ID, not by vendor name.