Executive brief
A security vulnerability has been identified in Moxa NPort 6000-G2 series serial device servers, which are used to connect industrial serial devices to networks. An attacker with low-level access credentials can send a malicious request that crashes the device or causes it to reboot unexpectedly. This can lead to a loss of connectivity for critical industrial equipment and disrupt operations.
Technical details
A denial-of-service (DoS) vulnerability exists in the WebSocket API of Moxa NPort 6000-G2 series serial device servers due to improper validation of input types (CWE-1287). The root cause is insufficient handling of JSON-based requests within the API component. A remote attacker with low-privileged authentication can exploit this by sending a specially crafted JSON request over the network. Successful exploitation results in service disruption or an unexpected hardware reboot. Moxa has released firmware version v1.2.0 to address this issue.
Affected products
- Moxa NPort 6000-G2 Series v1.1.0 and earlier
- Moxa NPort 6100-G2/6200-G2 Series v1.1.0 and earlier
- Moxa NPort 6400-G2 Series v1.1.0 and earlier
- Moxa NPort 6600-G2 Series v1.1.0 and earlier
Timeline
- 2026-06-16: advisory: Moxa published security advisory MPSA-268270
- 2026-06-16: disclosed: CVE-2026-10825 published to NVD dataset