CVE-2026-86325 PUBLISHED

Assigner: Moxa
Reserved: 07.09.2026 Published: 02.10.2026 Updated: 02.10.2026

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the account_name parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor Moxa
Product MGate MB3170 Series
Versions Default: unaffected
  • affected from 1.0 to 4.7 (incl.)
Vendor Moxa
Product MGate MB3270 Series
Versions Default: unaffected
  • affected from 1.0 to 4.7 (incl.)

Solutions

Moxa has developed appropriate solutions to address the vulnerability: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-269540-cve-2026-86325,-cve-2026-86326-two-vulnerabilities-in-protocol-gateways

References

Problem Types

  • CWE-121: Stack-based Buffer Overflow CWE

Impacts

  • CAPEC-24: Filter Failure through Buffer Overflow