Junglewise Threat Intelligence

CVE-2026-10825: Moxa NPort 6000-G2 Series denial of service in WebSocket API

CVE-2026-10825 · Severity: info · CVSS 7.1 · Published 2026-06-16

Vendors: Moxa.

Executive brief

A security vulnerability has been identified in Moxa NPort 6000-G2 series serial device servers, which are used to connect industrial serial devices to networks. An attacker with low-level access credentials can send a malicious request that crashes the device or causes it to reboot unexpectedly. This can lead to a loss of connectivity for critical industrial equipment and disrupt operations.

Technical details

A denial-of-service (DoS) vulnerability exists in the WebSocket API of Moxa NPort 6000-G2 series serial device servers due to improper validation of input types (CWE-1287). The root cause is insufficient handling of JSON-based requests within the API component. A remote attacker with low-privileged authentication can exploit this by sending a specially crafted JSON request over the network. Successful exploitation results in service disruption or an unexpected hardware reboot. Moxa has released firmware version v1.2.0 to address this issue.

Affected products

  • Moxa NPort 6000-G2 Series v1.1.0 and earlier
  • Moxa NPort 6100-G2/6200-G2 Series v1.1.0 and earlier
  • Moxa NPort 6400-G2 Series v1.1.0 and earlier
  • Moxa NPort 6600-G2 Series v1.1.0 and earlier

Timeline

  • 2026-06-16: advisory: Moxa published security advisory MPSA-268270
  • 2026-06-16: disclosed: CVE-2026-10825 published to NVD dataset

References