Missing Cryptographic Step Vulnerability in Moxa Embedded Linux Firmware for Industrial Computers
CVE-2026-9266
7HIGH
What is CVE-2026-9266?
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware used in industrial computers and controllers. This issue stems from an incomplete remediation of a prior vulnerability, leading to ineffective parameter encryption for TPM2 as a countermeasure. An attacker with invasive physical access can exploit this flaw by capturing TPM communications over the SPI bus, potentially revealing the LUKS disk encryption key in plaintext. It's important to note that while the attack enables the full compromise of the encrypted disk volume, it necessitates physical access to the device, as remote exploitation is not a viable threat.
Affected Version(s)
UC-1200A Series OS imageĀ (MIL3 Secure version) 1.0 <= 1.4