Junglewise Threat Intelligence

CVE-2026-10829: Moxa NPort W2150A/W2250A stack overflow in Server location parameter

CVE-2026-10829 · Severity: info · CVSS 8.6 · Published 2026-06-16

Vendors: Moxa.

Executive brief

Moxa NPort serial device servers, which are used to connect industrial serial equipment to Wi-Fi networks, are vulnerable to a critical security flaw. An attacker with administrative access can send specially crafted data to the device's web management interface to crash the system or take full control of it. If exploited, this could allow an attacker to disrupt industrial operations or manipulate data flowing through the device.

Technical details

A stack-based buffer overflow (CWE-121) exists in the web management interface of Moxa NPort W2150A-W4 and W2250A-W4 series devices. The vulnerability is located in the 'Server location' parameter on the Basic settings page due to insufficient validation of user-supplied input. An attacker with high privileges (PR:H) can exploit this over the network by submitting a crafted string that overflows the stack buffer, leading to memory corruption. Successful exploitation enables remote code execution with root-level permissions. A firmware patch (v1.5.1) is available for the W4 series, while older phased-out models require hardware replacement.

Affected products

  • Moxa NPort W2150A-W4 Series 1.5 and earlier
  • Moxa NPort W2250A-W4 Series 1.5 and earlier
  • Moxa NPort W2150A Series 2.3 and earlier
  • Moxa NPort W2250A Series 2.3 and earlier

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched: Firmware v1.5.1 released for W4 series

References

Related threats