Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Moxa Inc.

First CVE: Feb 18, 2011Active for: 15 yearsTotal CVEs: 289
45.7
VTI Score
High

Moxa Inc. is a prominent provider of industrial networking and automation equipment, spanning a broad portfolio of wireless access points, industrial routers, and embedded devices deployed across manufacturing, utilities, and critical infrastructure environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical-severity disclosures, reflecting the memory-safety and input-validation demands of embedded systems that often operate in safety-critical or network-critical contexts. The exposure concentrates in flagship products such as the AWK-3131A wireless access point and the EDR-810 industrial router, and recurs through weakness classes including OS command injection, exposure of sensitive information, cleartext transmission of credentials, and buffer-overflow conditions that are endemic to industrial firmware and edge-device codebases. Defenders should prioritize inventory of Moxa devices in operational technology networks and treat firmware updates as urgent; internet-facing instances warrant particular attention given the vendor's placement in critical infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
289
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Moxa Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2011
15 years ago
Most Recent CVE
Feb 5, 2026
169 days ago

Self-Reporting Analysis

Of all the CVEs published by Moxa Inc. as a CNA, 58.1% affect products that Moxa Inc. develops as a vendor.

58.1%
41.9%
Self-reported: 43 (58.1%)
Third-party: 31 (41.9%)

Of all the CVEs published that affect products developed by Moxa Inc., 14.9% are self-published by Moxa Inc. as a CNA.

14.9%
85.1%
Self-published: 43 (14.9%)
Other CNAs: 246 (85.1%)

Products(993 total)

Top CVEs

Signals from CVEs in this vendor scope (289 CVEs).

289 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4742HIGH
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFil
Feb 18, 201110.077NOYES
CVE-2010-4741HIGH
Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to execute arbitrary code via crafted data in a s
Feb 18, 20119.363NOYES
CVE-2022-40224HIGH
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to
Feb 7, 20237.559NONO
CVE-2017-7456HIGH
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.
Apr 14, 20177.552NOYES
CVE-2017-14459CRITICAL
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/clie
Apr 11, 20189.848NOYES
CVE-2016-9361CRITICAL
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions
Feb 13, 20179.847NOYES
CVE-2017-12128HIGH
An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause informati
May 14, 20187.544NONO
CVE-2017-7455HIGH
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
Apr 14, 20177.544NOYES
CVE-2018-19660HIGH
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A special
Dec 6, 20188.842NONO
CVE-2018-10700MEDIUM
An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows
Jun 7, 20196.140NONO
View all 289 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products289 CVEs
21%
55%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (4.5%)
Network258 (89.3%)
Unknown10 (3.5%)
Physical4 (1.4%)
Adjacent Network4 (1.4%)
Attack Complexity
Low266 (92.0%)
High13 (4.5%)
Unknown10 (3.5%)
User Interaction
None237 (82.0%)
Unknown10 (3.5%)
Required42 (14.5%)
Privileges Required
Low50 (17.3%)
High8 (2.8%)
None221 (76.5%)
Unknown10 (3.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (289 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
1.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Moxa Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Moxa Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Moxa Inc.'s Products

View all 7 CNAs →

Top CWEs