Stack-Based Buffer Overflow in Moxa Protocol Gateways
CVE-2026-86325

9.4CRITICAL

Key Information:

Vendor

Moxa

Vendor
CVE Published:
2 October 2026

What is CVE-2026-86325?

A stack-based buffer overflow vulnerability exists in the account management interface of Moxa protocol gateways. This issue arises from inadequate length validation of the 'account_name' parameter during account management requests. An authenticated read-only user could exploit this vulnerability by submitting a specially crafted account name that exceeds the limits of the internal stack buffer. This could lead to corruption of program execution flow, allowing an attacker to read sensitive information from device memory, such as credentials, and manipulate arbitrary memory contents, potentially leading to device unavailability.

Affected Version(s)

MGate MB3170 Series 1.0 <= 4.7

MGate MB3270 Series 1.0 <= 4.7

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.