[Control Systems] Moxa security advisory (AV26-938)
Canada's Cyber Centre (AV26-938) warns of out-of-bounds write flaw CVE-2026-15579 in Moxa TN-4500B Series Ethernet switches at or below v2.0.
The Canadian Centre for Cyber Security issued advisory AV26-938 for an out-of-bounds write vulnerability, CVE-2026-15579, affecting Moxa TN-4500B Series industrial Ethernet switches prior to or equal to version 2.0. Administrators are encouraged to review the linked Moxa security advisory and apply updates as they become available. No exploitation activity is reported.
- CVE-2026-15579 is an out-of-bounds write flaw in Moxa TN-4500B Series switches
- Affects versions prior to or equal to v2.0
- Cyber Centre urges administrators to review vendor guidance and apply updates
Vulnerabilities mentionedAll →
- CVE-2026-155798.8—Out-of-Bounds Write in Moxa Ethernet Switch Web Login Enables DoSpublished · Moxa Ethernet switches (some models; specific affected model families are not enumerated in the provided data)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15579 | Out-of-Bounds Write in Moxa Ethernet Switch Web Login Enables DoS An out-of-bounds write vulnerability (CWE-787) exists in some Moxa Ethernet switches due to improper validation of the length of the username field during web login processing. A remote, unauthenticated attacker can trigger it by submitting a specially crafted, overly long username to the switch's web login page, causing a buffer overflow. The impact is a crash of the authentication process, resulting in a Denial of Service of the switch's web authentication — CVSS 4.0 scores availability impact as High, with no confidentiality and only low integrity impact. Any operator running an affected Moxa Ethernet switch model is affected, particularly where the web management interface is reachable from untrusted networks. As of now, the flaw is not listed in CISA KEV, no public proof-of-concept is known, and no exploitation has been reported. |
Full article62 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-938
Date: September 18, 2026
As of September 18, 2026, Moxa is affected by a vulnerability in the following product:
- TN-4500B Series
- Prior to or equal to v2.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/control-systems-moxa-security-advisory-av26-938