AI analysis
An out-of-bounds write vulnerability (CWE-787) exists in some Moxa Ethernet switches due to improper validation of the length of the username field during web login processing. A remote, unauthenticated attacker can trigger it by submitting a specially crafted, overly long username to the switch's web login page, causing a buffer overflow. The impact is a crash of the authentication process, resulting in a Denial of Service of the switch's web authentication — CVSS 4.0 scores availability impact as High, with no confidentiality and only low integrity impact. Any operator running an affected Moxa Ethernet switch model is affected, particularly where the web management interface is reachable from untrusted networks. As of now, the flaw is not listed in CISA KEV, no public proof-of-concept is known, and no exploitation has been reported.
What to do: Check Moxa's advisory for CVE-2026-15579 to identify whether your switch models are affected and upgrade to the fixed firmware the vendor specifies. Until patching, restrict access to the switches' web management interface to trusted management networks via ACLs, VLAN segmentation, or firewall rules, and disable web login on devices that are managed another way. Monitor for repeated crashes or unavailability of the switch's web authentication service, which would indicate exploitation attempts.
Affected
| Moxa Ethernet switches (some models; specific affected model families are not enumerated in the provided data) | — |
Estimated exposure
largetens of thousands to low hundreds of thousands of deployed switches (est.); only units with the web login interface reachable by attackers are exploitable — Moxa is a major industrial Ethernet switch vendor with a large installed base across manufacturing, energy, rail, and transportation networks, and public internet-wide scans routinely surface tens of thousands of Moxa devices, though most…
Description
An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This may allow a remote attacker to submit a specially crafted overly long input, triggering a buffer overflow that can cause the authentication process to crash and result in a Denial of Service (DoS) attack.