Stack-Based Buffer Overflow Vulnerability in Moxa NPort W2150A-W4/W2250A-W4 Series
CVE-2026-10829

8.6HIGH

What is CVE-2026-10829?

A stack-based buffer overflow vulnerability exists in the Moxa NPort W2150A-W4 and W2250A-W4 Series products due to improper input validation of user-submitted data in the 'Server location' parameter on the Basic settings page. An attacker can exploit this flaw by sending specially crafted input to the web service, leading to potential memory corruption. If successfully exploited, this vulnerability may allow for remote code execution on the affected system with elevated privileges, raising significant security concerns for users of these products.

Affected Version(s)

NPort W2150A-W4/W2250A-W4 Series 1.0 <= 1.5

NPort W2150A/W2250A Series 1.0 <= 2.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Remi ONNO of CS GROUP France (Sopra Steria Group)
.