Stack-Based Buffer Overflow Vulnerability in Moxa NPort W2150A-W4/W2250A-W4 Series
CVE-2026-10829
8.6HIGH
Key Information:
- Vendor
Moxa
- Vendor
- CVE Published:
- 16 June 2026
What is CVE-2026-10829?
A stack-based buffer overflow vulnerability exists in the Moxa NPort W2150A-W4 and W2250A-W4 Series products due to improper input validation of user-submitted data in the 'Server location' parameter on the Basic settings page. An attacker can exploit this flaw by sending specially crafted input to the web service, leading to potential memory corruption. If successfully exploited, this vulnerability may allow for remote code execution on the affected system with elevated privileges, raising significant security concerns for users of these products.
Affected Version(s)
NPort W2150A-W4/W2250A-W4 Series 1.0 <= 1.5
NPort W2150A/W2250A Series 1.0 <= 2.3
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Remi ONNO of CS GROUP France (Sopra Steria Group)