CVE-2026-10831 PUBLISHED

Improper Authorization of Break Signal Commands in Devices

Assigner: Moxa
Reserved: 04.06.2026 Published: 16.06.2026 Updated: 16.06.2026

A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not properly validate whether a sender is associated with a valid data port session before accepting break signal commands. A remote attacker with network access can send crafted requests to disrupt serial communication for an active user session.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L
CVSS Score: 6.9

Product Status

Vendor Moxa
Product NPort 6000 Series
Versions Default: unaffected
  • affected from 1.0 to 2.3 (incl.)
Vendor Moxa
Product CN2600 Series
Versions Default: unaffected
  • affected from 1.0 to 4.6 (incl.)

Solutions

Please refer to the security advisory: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-262370-cve-2026-10831-improper-authorization-vulnerability-in-serial-device-servers

Credits

  • Artur Witek finder

References

Problem Types

  • CWE-862: Missing Authorization CWE

Impacts

  • CAPEC-212: Functionality Misuse