Home / CVEs we hold for Moxa CVEs we hold for Moxa Records whose assigning authority named Moxa as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-10831 Improper Authorization of Break Signal Commands in Devices Moxa CN2600 Series CVE-2026-10825 Improper JSON Input Validation in WebSocket API Leads to Denial of Service Moxa NPort 6000-G2 Series CVE-2025-9315 Unauthenticated Device Registration Vulnerability in MXsecurity Series Moxa MXsecurity Series CVE-2025-5191 Unquoted Search Path Vulnerability in the Utility for Industrial Computers (Windows) Moxa Utility for DRP-C100 Series CVE-2025-0676 Commend Injection Leading to Privilege Escalation Moxa NAT-102 Series CVE-2025-0193 Stored Cross-site Scripting (XSS) Vulnerability in the MGate 5121/5122/5123 Series Moxa MGate 5123 Series CVE-2024-9139 OS Command Injection in Restricted Command Moxa EDR-810 Series CVE-2024-9138 Privilege Escalation in Cellular Router, Secure Router, and Network Security Appliances Moxa TN-4900 Series CVE-2024-9137 Moxa Service Missing Authentication for Critical Function Moxa TN-G6500 Series CVE-2024-7695 Out-of-bounds Write Vulnerability Moxa TN-G6500 Series CVE-2024-6787 MXview One Series vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition Moxa MXview One Series CVE-2024-6786 MXview One Series vulnerable to Path Traversal Moxa MXview One Series CVE-2024-6785 MXview One and MXview One Central Manager Series store cleartext credentials in a local file Moxa MXview One Central Manager Series CVE-2024-4740 MXsecurity Use of Hard-coded Credentials Moxa MXsecurity Series CVE-2024-4739 MXsecurity License Generation Function Disclosure Moxa MXsecurity Series CVE-2024-4641 OnCell G3470A-LTE Series: Authenticated Format String Errors Moxa OnCell G3150A-LTE Series CVE-2024-4640 OnCell G3470A-LTE Series: Authenticated Command Injection via sendTestEmail Moxa OnCell G3150A-LTE Series CVE-2024-4639 OnCell G3470A-LTE Series: Authenticated Command Injection via webDelIPSec Moxa OnCell G3150A-LTE Series CVE-2024-4638 OnCell G3470A-LTE Series: Authenticated Command Injection via webUploadKey Moxa OnCell G3470A-LTE Series CVE-2024-3576 NPort 5100A Series Store XSS Vulnerability Moxa NPort 5100A Series CVE-2024-12297 Frontend Authorization Logic Disclosure Vulnerability Moxa PT-G7828 Series CVE-2024-1220 NPort W2150A/W2250A Series Web Server Stack-based Buffer Overflow Vulnerability Moxa NPort W2150A/W2250A Series CVE-2024-0387 EDS-4000/G4000 Series IP Forwarding Vulnerability Moxa EDS-G4014 Series CVE-2023-6094 OnCell G3150A-LTE Series: Web Server Transmits Cleartext Credentials Moxa OnCell G3150A-LTE Series CVE-2023-6093 OnCell G3150A-LTE Series: Clickjacking Vulnerability Moxa OnCell G3150A-LTE Series CVE-2023-5962 ioLogik E1200 Series: Weak Cryptographic Algorithm Vulnerability Moxa ioLogik E1200 Series CVE-2023-5961 ioLogik E1200 Series: Cross-Site Request Forgery (CSRF) Vulnerability Moxa ioLogik E1200 Series CVE-2023-5627 Incorrect Implementation of Authentication Algorithm Vulnerability Moxa NPort 6000 Series CVE-2023-4929 NPort 5000 Series Firmware Improper Validation of Integrity Check Vulnerability Moxa NPort P5150A Series CVE-2023-4452 Web Server Buffer Overflow Vulnerability Moxa EDR G903 Series CVE-2023-4230 ioLogik 4000 Series: Server Banner Information Disclosure Moxa ioLogik 4000 Series CVE-2023-4229 ioLogik 4000 Series: Session Headers Not Implemented Moxa ioLogik 4000 Series CVE-2023-4228 ioLogik 4000 Series: Session Cookies Attribute Not Set Properly Moxa ioLogik 4000 Series CVE-2023-4227 ioLogik 4000 Series: Existence of an Unauthorized Service Moxa ioLogik 4000 Series CVE-2023-4217 Session cookies attribute not set properly Moxa PT-G503 Series CVE-2023-4204 NPort IAW5000A-I/O Series Hardcoded Credential Vulnerability Moxa NPort IAW5000A-I/O Series CVE-2023-39983 MXsecurity Register Database Pollution Moxa MXsecurity Series CVE-2023-39981 MXsecurity Device Information Disclosure Moxa MXsecurity Series CVE-2023-39980 MXsecurity Authenticated Information Disclosure Due to SQL Injection Moxa MXsecurity Series CVE-2023-34217 Second Order Command-injection Vulnerability in the Certificate-delete Function Moxa NAT-102 Series CVE-2023-34216 Second Order Command-injection Vulnerability in the Key-delete Function Moxa NAT-102 Series CVE-2023-34215 Second Order Command-injection Vulnerability in the Certificate-generation Function Moxa TN-5900 Series CVE-2023-34214 Second Order Command-injection Vulnerability in the Certificate-generation Function Moxa EDR-G903 Series CVE-2023-34213 Second Order Command-injection Vulnerability in the Key-generation Function Moxa TN-5900 Series CVE-2023-3336 TN-5900 Series User Enumeration Vulnerability Moxa TN-5900 Series CVE-2023-33239 Second Order Command-injection Vulnerability in the Key-generation Function Moxa NAT-102 Series CVE-2023-33238 Command-injection Vulnerability in Certificate Management Moxa NAT-102 Series CVE-2023-33237 Authentication Bypass Without Administrator Privilege Moxa TN-5900 Series CVE-2023-33236 MXsecurity Hardcoded Credential Vulnerability Moxa MXsecurity Series CVE-2023-33235 MXsecurity Command Injection Vulnerability Moxa MXsecurity Series CVE-2023-28697 Moxa MiiNePort E1 - Broken Access Control Moxa MiiNePort E1 CVE-2022-41313 no title held Moxa SDS-3008 Series Industrial Ethernet Switch CVE-2022-41312 no title held Moxa SDS-3008 Series Industrial Ethernet Switch CVE-2022-41311 no title held Moxa SDS-3008 Series Industrial Ethernet Switch CVE-2022-40693 no title held Moxa SDS-3008 Series Industrial Ethernet Switch CVE-2022-40691 no title held Moxa SDS-3008 Series Industrial Ethernet Switch CVE-2022-40224 no title held Moxa SDS-3008 Series Industrial Ethernet Switch CVE-2021-4161 ICSA-21-357-01 Moxa MGate Protocol Gateways Moxa MGate MB3480 Series CVE-2021-38460 Moxa MXview Network Management Software Moxa MXview Network Management Software CVE-2021-38458 Moxa MXview Network Management Software Moxa MXview Network Management Software CVE-2021-38456 Moxa MXview Network Management Software Moxa MXview Network Management Software CVE-2021-38454 Moxa MXview Network Management Software Moxa MXview Network Management Software CVE-2021-38452 Moxa MXview Network Management Software Moxa MXview Network Management Software CVE-2021-32976 Moxa NPort IAW5000A-I/O Series Serial Device Server Stack-based Buffer Overflow Moxa NPort IAW5000A-I/O series firmware CVE-2021-32974 Moxa NPort IAW5000A-I/O Series Serial Device Server Improper Input Validation Moxa NPort IAW5000A-I/O series firmware CVE-2021-32970 Moxa NPort IAW5000A-I/O Series Serial Device Server Improper Input Validation Moxa NPort IAW5000A-I/O series firmware CVE-2021-32968 Moxa NPort IAW5000A-I/O Series Serial Device Server Classic Buffer Overflow Moxa NPort IAW5000A-I/O Series firmware CVE-2020-7007 no title held n/a Moxa EDS-G516E Series firmware, Version 5.2 or lower CVE-2020-7003 no title held n/a Moxa ioLogik 2500 series firmware, Version 3.0 or… CVE-2020-7001 no title held n/a Moxa EDS-G516E Series firmware, Version 5.2 or lower CVE-2020-6999 no title held n/a Moxa EDS-G516E Series firmware, Version 5.2 or lower CVE-2020-6997 no title held n/a Moxa EDS-G516E Series firmware, Version 5.2 or lower CVE-2020-6995 no title held n/a Moxa PT-7528 series firmware, Version 4.0 or lower… CVE-2020-6993 no title held n/a Moxa PT-7528 series firmware, Version 4.0 or lower… CVE-2020-6991 no title held n/a Moxa EDS-G516E Series firmware, Version 5.2 or lower CVE-2020-6989 no title held n/a Moxa PT-7528 series firmware, Version 4.0 or lower… CVE-2020-6987 no title held n/a Moxa PT-7528 series firmware, Version 4.0 or lower… CVE-2020-6985 no title held n/a Moxa PT-7528 series firmware, Version 4.0 or lower… CVE-2020-6983 no title held n/a Moxa PT-7528 series firmware, Version 4.0 or lower… CVE-2020-6981 no title held n/a Moxa EDS-G516E Series firmware, Version 5.2 or lower CVE-2020-6979 no title held n/a Moxa EDS-G516E Series firmware, Version 5.2 or lower CVE-2019-18242 no title held n/a Moxa ioLogik 2500 series firmware, Version 3.0 or… CVE-2019-18238 no title held n/a Moxa ioLogik 2500 series firmware, Version 3.0 or… CVE-2018-18396 no title held Moxa ThingsPro IIoT Gateway and Device Management Software… CVE-2018-18395 no title held Moxa ThingsPro IIoT Gateway and Device Management Software… CVE-2018-18394 no title held Moxa ThingsPro IIoT Gateway and Device Management Software… CVE-2018-18393 no title held Moxa ThingsPro IIoT Gateway and Device Management Software… CVE-2018-18392 no title held Moxa ThingsPro IIoT Gateway and Device Management Software… CVE-2018-18391 no title held Moxa ThingsPro IIoT Gateway and Device Management Software… CVE-2018-18390 no title held Moxa ThingsPro IIoT Gateway and Device Management Software… CVE-2016-8727 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8726 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8725 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8724 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8723 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8722 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8720 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8719 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8718 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8716 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8712 no title held Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n… CVE-2016-8379 no title held n/a Moxa ioLogik E1200 Series before 3.12 CVE-2016-8372 no title held n/a Moxa ioLogik E1200 Series before 3.12 CVE-2016-8359 no title held n/a Moxa ioLogik E1200 Series before 3.12 CVE-2016-8350 no title held n/a Moxa ioLogik E1200 Series before 3.12 CVE-2016-8346 no title held n/a Moxa EDR-810 Industrial Secure Router CVE-2016-5819 no title held Moxa OnCell G3111/G3151/G3211/G3251 Series 196 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.