Out-of-Bounds Write Vulnerability in Moxa Ethernet Switches
CVE-2026-15579

8.8HIGH

Key Information:

Vendor

Moxa

Vendor
CVE Published:
18 September 2026

What is CVE-2026-15579?

An out-of-bounds write vulnerability has been identified in certain Moxa Ethernet switches due to inadequate validation of the username field length during web login processes. This weakness allows a remote attacker to exploit the vulnerability by sending a specially crafted, excessively long input. The result can lead to a buffer overflow, causing the system's authentication process to fail and potentially triggering a Denial of Service (DoS) situation.

Affected Version(s)

TN-4500B Series 1.0 <= 2.0

TN-4500B Series 2.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mask Lu
.