Description
A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.
Published: 2026-10-02
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Moxa has developed appropriate solutions to address the vulnerability: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-269540-cve-2026-86325,-cve-2026-86326-two-vulnerabilities-in-protocol-gateways

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Moxa MGate Account Management Interface

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.
First Time appeared Moxa
Moxa mgate Mb3170 Series
Moxa mgate Mb3270 Series
Weaknesses CWE-121
CPEs cpe:2.3:a:moxa:mgate_mb3170_series:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:mgate_mb3270_series:*:*:*:*:*:*:*:*
Vendors & Products Moxa
Moxa mgate Mb3170 Series
Moxa mgate Mb3270 Series
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Moxa Mgate Mb3170 Series Mgate Mb3270 Series
cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published:

Updated: 2026-10-02T10:49:43.686Z

Reserved: 2026-09-07T06:34:02.910Z

Link: CVE-2026-86325

cve-icon Vulnrichment

Updated: 2026-10-02T10:49:39.684Z

cve-icon NVD

Status : Received

Published: 2026-10-02T11:17:36.173

Modified: 2026-10-02T11:17:36.173

Link: CVE-2026-86325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T11:30:18Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow