Junglewise Threat Intelligence

CVE-2026-10828: Moxa NPort W2150A/W2250A format string vulnerability in alias parameter

CVE-2026-10828 · Severity: info · CVSS 6.9 · Published 2026-06-16

Vendors: Moxa.

Executive brief

Moxa NPort serial device servers, which connect industrial serial equipment to wireless networks, contain a security flaw in their web configuration interface. An attacker with administrative privileges can exploit this flaw to view sensitive information stored in the device's memory. This could lead to the exposure of system secrets or help an attacker bypass other security protections to gain further control over the device.

Technical details

A format string vulnerability (CWE-134) exists in the 'alias' parameter of the Serial Param configuration page within the web-based management interface. The issue results from insufficient validation of user-supplied input before it is processed by a format-string-aware function. A remote attacker with high privileges (PR:H) can submit crafted input containing format specifiers to leak sensitive memory contents. This disclosure can be used to identify critical memory addresses, effectively bypassing Address Space Layout Randomization (ASLR) and facilitating further exploitation. A security patch (v1.5.1) is available for the W4 series, while older phased-out models require hardware replacement.

Affected products

  • Moxa NPort W2150A-W4 Series 1.5 and prior
  • Moxa NPort W2250A-W4 Series 1.5 and prior
  • Moxa NPort W2150A Series 2.3 and prior
  • Moxa NPort W2250A Series 2.3 and prior

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched: Firmware v1.5.1 released for W4 series

References

Related threats