Missing Cryptographic Step Vulnerability in Moxa Embedded Linux Firmware for Industrial Computers
CVE-2026-9266

7HIGH

Key Information:

Vendor

Moxa

Vendor
CVE Published:
12 June 2026

What is CVE-2026-9266?

A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware used in industrial computers and controllers. This issue stems from an incomplete remediation of a prior vulnerability, leading to ineffective parameter encryption for TPM2 as a countermeasure. An attacker with invasive physical access can exploit this flaw by capturing TPM communications over the SPI bus, potentially revealing the LUKS disk encryption key in plaintext. It's important to note that while the attack enables the full compromise of the encrypted disk volume, it necessitates physical access to the device, as remote exploitation is not a viable threat.

Affected Version(s)

UC-1200A Series OS imageĀ (MIL3 Secure version) 1.0 <= 1.4

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cyloq
.