A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input in the "Server location" parameter on the Basic settings page. An attacker could exploit this vulnerability by sending crafted input to the web service, resulting in memory corruption. Successful exploitation of this vulnerability could allow remote code execution on the target system with root privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input in the "Server location" parameter on the Basic settings page. An attacker could exploit this vulnerability by sending crafted input to the web service, resulting in memory corruption. Successful exploitation of this vulnerability could allow remote code execution on the target system with root privileges. | |
| First Time appeared |
Moxa
Moxa nport W2150a-w4 W2250a-w4 Series Moxa nport W2150a W2250a Series |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:moxa:nport_w2150a-w4_w2250a-w4_series:*:*:*:*:*:*:*:* cpe:2.3:a:moxa:nport_w2150a_w2250a_series:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Moxa
Moxa nport W2150a-w4 W2250a-w4 Series Moxa nport W2150a W2250a Series |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Moxa
Published:
Updated: 2026-06-16T12:16:54.768Z
Reserved: 2026-06-04T09:42:27.847Z
Link: CVE-2026-10829
Updated: 2026-06-16T12:16:45.230Z
Status : Received
Published: 2026-06-16T12:16:25.967
Modified: 2026-06-16T12:16:25.967
Link: CVE-2026-10829
No data.
OpenCVE Enrichment
No data.