PatchSiren cyber security CVE debrief
CVE-2026-10828 Moxa CVE debrief
A format string vulnerability has been found in the 'alias' parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections.
- Vendor
- Moxa
- Product
- NPort W2150A-W4/W2250A-W4 Series
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-16
- Original CVE updated
- 2026-06-16
- Advisory published
- 2026-06-16
- Advisory updated
- 2026-06-16
Who should care
Administrators and users of Moxa NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior should apply patches or mitigations to prevent exploitation.
Technical summary
The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. It is identified as CWE-134, Use of Externally-Controlled Format String.
Defensive priority
MEDIUM
Recommended defensive actions
- Apply patches or updates provided by the vendor to address the format string vulnerability.
- Implement input validation and sanitization for user-supplied input.
- Monitor network traffic and system logs for suspicious activity.
Evidence notes
The CVE record and details were obtained from the official CVE website and the National Vulnerability Database (NVD).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-10828 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-10828
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-10828 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10828
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-261910-cve-2026-10828,-cve-2026-10829-use-of-externally-controlled-format-string-and-stack-based-buffer-overflow-v
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.