Junglewise Threat Intelligence

CVE-2026-9266: Moxa Industrial Computers missing cryptographic step in TPM communication

CVE-2026-9266 · Severity: info · CVSS 7 · Published 2026-06-12

Vendors: Moxa.

Executive brief

A security flaw in Moxa industrial computers and controllers could allow an attacker with physical access to bypass disk encryption. By opening the device and monitoring internal hardware communications, an attacker can retrieve the encryption keys used to protect stored data. This could lead to a full compromise of the information stored on the device, though it requires specialized equipment and direct physical tampering.

Technical details

A Missing Required Cryptographic Step (CWE-325) exists in Moxa's embedded Linux firmware (MIL) due to an incomplete remediation of a previous vulnerability. While TPM2 parameter encryption was introduced as a fix, an omission in the authorization session configuration renders this encryption ineffective. An attacker with invasive physical access can sniff the SPI bus to capture TPM communications and derive the LUKS plaintext disk encryption key. This allows for the full decryption of the disk volume. The attack is local/physical only and cannot be performed over a network. Moxa has released updated firmware images and kernel packages to address the configuration error.

Affected products

  • Moxa UC-1200A Series OS image (MIL3/MIL4) v1.4 and earlier (MIL3); v4.0.0 and earlier (MIL4)
  • Moxa UC-2200A Series OS image (MIL3/MIL4) v1.4 and earlier (MIL3); v4.0.0 and earlier (MIL4)
  • Moxa UC-3400A Series OS image (MIL3/MIL4) v1.2 and earlier (MIL3); v4.0.0 and earlier (MIL4)
  • Moxa UC-4400A Series OS image (MIL3) v1.3 and earlier
  • Moxa UC-8200 Series OS image (MIL3) v1.5 and earlier
  • Moxa V1200 Series OS image (MIL3) v1.2.0 and earlier
  • Moxa V3200 Series OS image (MIL3) v1.1 and earlier
  • Moxa V3400 Series OS image (MIL3) v1.1 and earlier
  • Moxa V2406C Series OS image (MIL2) v1.2 and earlier

Timeline

  • 2026-06-12: advisory: Moxa published security advisory MPSA-266240
  • 2026-06-12: disclosed: CVE-2026-9266 published

References