ZeroHour

Vulnerabilities

275 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0715
+1 in the same advisory: …0714
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device.

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.

NVD description · AI analysis pending
7.0<1%
  • moxa uc-1222a firmware
  • moxa uc-2222a-t-us firmware
  • moxa uc-2222a-t firmware
  • +1 more
CVE-2024-4739
+1 in the same advisory: …4740
The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior vulnerable.

The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior vulnerable. By acquiring a valid authenticator, an attacker can pose as an authorized user and successfully access the resource.

NVD description · AI analysis pending
7.5<1%
  • moxa mxsecurity
CVE-2024-6785
+2 in the same advisory: …6786 …6787
The configuration file stores credentials in cleartext.

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

NVD description · AI analysis pending
6.8
group max
<1%
  • moxa mxview one
  • moxa mxview one central manager
CVE-2024-4641
+2 in the same advisory: …4639 …4640
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an ar

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.

NVD description · AI analysis pending
9.8
group max
<1%
  • moxa oncell g3470a-lte-us-t firmware
  • moxa oncell g3470a-lte-eu firmware
  • moxa oncell g3470a-lte-eu-t firmware
  • +1 more
CVE-2024-4638
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload functio

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.

NVD description · AI analysis pending
8.8<1%
  • moxa oncell g3470a-lte-eu-t firmware
  • moxa oncell g3470a-lte-eu firmware
  • moxa oncell g3470a-lte-us firmware
  • +1 more
CVE-2024-1220
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit t

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.

NVD description · AI analysis pending
7.5<1%
  • moxa nport w2150a firmware
  • moxa nport w2250a firmware
  • moxa nport w2150a-t firmware
  • +1 more
CVE-2024-0387
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate.

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

NVD description · AI analysis pending
6.5<1%
  • moxa eds-4008 firmware
  • moxa eds-4009 firmware
  • moxa eds-4012 firmware
  • +1 more
CVE-2023-6093
+1 in the same advisory: …6094
A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior.

A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This vulnerability may lead the attacker to trick the user into interacting with the application.

NVD description · AI analysis pending
6.1
group max
<1%
  • moxa oncell g3150a-lte firmware
CVE-2023-5961
+1 in the same advisory: …5962
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior.

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.

NVD description · AI analysis pending
8.8
group max
<1%
  • moxa iologik e1210 firmware
  • moxa iologik e1211 firmware
  • moxa iologik e1212 firmware
  • +1 more
CVE-2023-4217
+1 in the same advisory: …5035
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected applicatio

A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

NVD description · AI analysis pending
5.3<1%
  • moxa eds-g503 firmware
CVE-2023-5627
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable.

A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web service.

NVD description · AI analysis pending
7.5<1%
  • moxa nport 6150-t firmware
  • moxa nport 6150 firmware
  • moxa nport 6250-m-sc-t firmware
  • +1 more
CVE-2023-4452
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability.

A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.

NVD description · AI analysis pending
7.5<1%
  • moxa edr-g903 firmware
  • moxa edr-g903-t firmware
  • moxa edr-g902 firmware
  • +1 more
CVE-2023-4929
All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability.

All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.

NVD description · AI analysis pending
8.8<1%
  • moxa nport 5150ai-m12-ct-t firmware
  • moxa nport 5250ai-m12-ct-t firmware
  • moxa nport 5150ai-m12-t firmware
  • +1 more
CVE-2023-39979
+4 in the same advisory: …39980 …39981 …39982 …39983
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication.

There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.

NVD description · AI analysis pending
9.8
group max
<1%
  • moxa mxsecurity
CVE-2023-4227
+3 in the same advisory: …4230 …4229 …4228
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to p

A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized manipulation of sensitive information. The vulnerability is attributed to the presence of an unauthorized service, which could potentially enable unauthorized access to the. device.

NVD description · AI analysis pending
6.5
group max
<1%
  • moxa iologik e4200 firmware
CVE-2023-33239
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability.

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.

NVD description · AI analysis pending
9.8
group max
1%
  • moxa tn-5900 firmware
  • moxa tn-4900 firmware
CVE-2023-4204
NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and in

NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presence of a hardcoded key, which could potentially facilitate firmware manipulation.

NVD description · AI analysis pending
9.8<1%
  • moxa nport iaw5000a-i\/o firmware
CVE-2023-3336
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability.

TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.

NVD description · AI analysis pending
5.3<1%
  • moxa tn-5900 firmware
CVE-2023-33236
+1 in the same advisory: …33235
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability.

MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.

NVD description · AI analysis pending
9.8
group max
<1%
  • moxa mxsecurity
CVE-2023-28697
Moxa MiiNePort E1 has a vulnerability of insufficient access control.

Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.

NVD description · AI analysis pending
9.8<1%
  • moxa miineport e1 firmware
CVE-2023-1257
An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS.

An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.

NVD description · AI analysis pending
6.8<1%
  • moxa uc-2101-lx firmware
  • moxa uc-2102-lx firmware
  • moxa uc-2102-t-lx firmware
  • +1 more
CVE-2022-40693
+4 in the same advisory: …41312 …41313 …41311 …40691
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1.

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • moxa sds-3008 firmware
  • moxa sds-3008-t firmware