Executive brief
Moxa NPort and CN2600 serial device servers, which connect legacy serial equipment to modern networks, are vulnerable to a denial-of-service attack. An attacker can send unauthorized commands to the device's management port to interrupt active data sessions. This can disrupt industrial operations or communication between connected hardware and the central network.
Technical details
A missing authorization vulnerability (CWE-862) exists in the command interface of Moxa NPort and CN2600 serial device servers. The device fails to validate whether a sender on the command port is associated with an active data port session before processing 'break signal' commands. A remote, unauthenticated attacker can exploit this by sending crafted requests over the network to the command port, resulting in the disruption of serial communication for legitimate users. Security patches are available via Moxa Technical Support (v2.3.9 for NPort 6000 and v4.6.11 for CN2600).
Affected products
- Moxa NPort 6000 Series (6100/6200/6400/6600) Firmware v2.3 and earlier
- Moxa CN2600 Series Firmware v4.6 and earlier
Timeline
- 2026-06-16: advisory: Moxa released security advisory MPSA-262370
- 2026-06-16: disclosed: CVE-2026-10831 published