Format String Vulnerability in Moxa NPort W2150A-W4/W2250A-W4 Series
CVE-2026-10828

6.9MEDIUM

What is CVE-2026-10828?

A format string vulnerability exists in the 'alias' parameter of the Serial Param configuration page in the Moxa NPort W2150A-W4 and W2250A-W4 Series, version 1.5 and earlier. This vulnerability arises from inadequate input validation and the erroneous treatment of externally provided format strings. By providing specially crafted input to the web service, an attacker could reveal sensitive memory data, potentially disclosing critical memory addresses and circumventing Address Space Layout Randomization (ASLR) protections. Prompt remediation is necessary to guard against exploitation risks and preserve system integrity.

Affected Version(s)

NPort W2150A-W4/W2250A-W4 Series 1.0 <= 1.5

NPort W2150A/W2250A Series 1.0 <= 2.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Remi ONNO of CS GROUP France (Sopra Steria Group)
.