CVE-2026-15579 PUBLISHED

Assigner: Moxa
Reserved: 13.07.2026 Published: 18.09.2026 Updated: 18.09.2026

An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This may allow a remote attacker to submit a specially crafted overly long input, triggering a buffer overflow that can cause the authentication process to crash and result in a Denial of Service (DoS) attack.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor Moxa
Product TN-4500B Series
Versions Default: unaffected
  • affected from 1.0 to 2.0 (incl.)
  • Version 2.1 is unaffected

Solutions

Refer to Moxa's security advisory: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-252620-cve-2026-15579-out-of-bounds-write-vulnerability-in-ethernet-switch

Credits

  • Mask Lu finder

References

Problem Types

  • CWE-787: Out-of-bounds Write CWE

Impacts

  • CAPEC-24: Filter Failure through Buffer Overflow