PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10828 Moxa CVE debrief

A format string vulnerability has been found in the 'alias' parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections.

Vendor
Moxa
Product
NPort W2150A-W4/W2250A-W4 Series
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-16
Original CVE updated
2026-06-16
Advisory published
2026-06-16
Advisory updated
2026-06-16

Who should care

Administrators and users of Moxa NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior should apply patches or mitigations to prevent exploitation.

Technical summary

The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. It is identified as CWE-134, Use of Externally-Controlled Format String.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply patches or updates provided by the vendor to address the format string vulnerability.
  • Implement input validation and sanitization for user-supplied input.
  • Monitor network traffic and system logs for suspicious activity.

Evidence notes

The CVE record and details were obtained from the official CVE website and the National Vulnerability Database (NVD).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10828 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10828

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10828 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10828

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-261910-cve-2026-10828,-cve-2026-10829-use-of-externally-controlled-format-string-and-stack-based-buffer-overflow-v

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.