As of June 15, 2022, this site no longer supports Internet Explorer. Please use another browser for the best experience on our site.

Product support

Security Advisories

SUMMARY

CVE-2026-86325, CVE-2026-86326: Two Vulnerabilities in Protocol Gateways

This security advisory addresses two vulnerabilities identified in protocol gateways.

CVE-2026-86325

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

CVE-2026-86326

An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful exploitation could allow the attacker to execute unauthorized code, compromise the integrity and availability of the device, and persist malicious modifications across subsequent firmware updates.

Given the high severity of these issues, users should apply the solutions immediately to reduce security risks.

 

The Identified Vulnerability Type and Potential Impact 

CVE ID Vulnerability Type Impact
CVE-2026-86325

CWE-121: Stack-based Buffer Overflow

CAPEC-24: Filter Failure through Buffer Overflow
CVE-2026-86326 CWE-347: Improper Verification of Cryptographic Signature CAPEC-475: Signature Spoofing by Improper Validation

Vulnerability Scoring Details 

CVE ID
Base Score
Vector
Severity

Unauthenticated

Remote Exploits

CVE-2026-86325

CVSS 4.0: 9.4

AV:N/AC:L/AT:N/PR:L/UI:N/

VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Critical No
CVE-2026-86326 CVSS 4.0: 8.6

AV:N/AC:L/AT:N/PR:H/UI:N/

VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

High No
AFFECTED PRODUCTS AND SOLUTIONS

Solutions

Moxa has developed appropriate solutions to address the vulnerability. The solutions for the affected products are listed in the following table: 

Product Series Affected Versions Solutions

MGate 3000 Series and MGate 5217 Series

  • MGate MB3170 Series
  • MGate MB3270 Series
  • MGate MB3180 Series
  • MGate MB3280 Series
  • MGate MB3480 Series
  • MGate MB3660 Series
  • MGate 5217 Series

Firmware

  • v4.7 and earlier
  • v4.7 and earlier
  • v2.7 and earlier
  • v4.6 and earlier
  • v4.5 and earlier
  • v3.4 and earlier
  • v1.5 and earlier

(affected by CVE-2026-86325)

Please contact Moxa Technical Support for the security patch

  • v4.7.1
  • v4.7.1
  • v2.7.1
  • v4.6.3
  • v4.5.1
  • v3.4.5
  • v1.5.5

MGate 3000 Series and MGate 5000 Series

  • MGate MB3170/MB3270 Series
  • MGate MB3180/MB3280/MB3480 Series
  • MGate MB3660 Series
  • MGate EIP3170/EIP3270 Series
  • MGate 5101-PBM-MN Series
  • MGate 5102-PBM-PN Series
  • MGate 5103 Series
  • MGate 5105-MB-EIP Series
  • MGate 5109 Series
  • MGate 5111 Series
  • MGate 5114 Series
  • MGate 5118 Series
  • MGate 5119 Series
  • MGate 5216 Series
  • MGate 5217 Series
  • MGate W5108/W5208 Series (phased-out product)

All firmware versions

(affected by CVE-2026-86326)

Please refer to Mitigations

 

Mitigations

For CVE-2026-86325, 

  • For users who may not be able to perform a firmware update, we provide the following recommended mitigation measures as an alternative to mitigate the risk associated with the vulnerability.
  • Refer to the General Security Recommendations section to further strengthen your security context.

 

For CVE-2026-86326, 

  • Users are advised to follow the applicable Security Hardening Guide for the MGate MB3000 or MGate 5000 Series when obtaining and updating firmware. The guides provide recommendations for securely obtaining firmware from official Moxa sources and performing firmware updates. Users should follow the applicable guidance to ensure that the correct and trusted firmware is obtained and that firmware updates are performed securely. For detailed mitigation guidance, please refer to the following Security Hardening Guides:
    • The Security Hardening Guide for the MGate 5000 Series
    • The Security Hardening Guide for the MGate MB3000 Series

 

General Security Recommendations

To safeguard devices and networks, we recommend implementing the following recommendations to mitigate potential risks:

  1. Restrict Network Access
    • Use firewalls or access control lists (ACLs) to limit communication to trusted IP addresses and networks.
    • Segregate operational networks from other networks (e.g., enterprise networks) using VLANs or physical separation.
  2. Minimize Exposure
    • Avoid exposing devices directly to the Internet.
    • Disable unused network services and ports to reduce the attack surface.
  3. Enhance Device Authentication and Access Control
    • Implement multi-factor authentication (MFA) for accessing critical systems.
    • Use role-based access control (RBAC) to enforce the principle of least privilege.
    • Prohibit the use of weak passwords and enforce a password policy that includes password complexity requirements, periodic password changes, and restrictions on password reuse.
  4. Regularly Update Firmware and Software
    • Keep devices updated with the latest firmware versions and security patches.
    • Establish a regular patch management schedule to address newly identified vulnerabilities.
  5. Secure Remote Access
    • Use encrypted communication protocols (e.g., VPN, SSH) for remote access.
    • Restrict remote access to authorized personnel only and enforce strong authentication mechanisms.
  6. Implement Anomaly Detection Techniques
    • Monitor network traffic and device behavior for unusual or unauthorized activities.
    • Use tools or techniques that can identify anomalies and provide alerts for potential threats.
  7. Implement Logging and Monitoring
    • Enable event logging and maintain audit trails on devices.
    • Regularly review logs for anomalies and unauthorized access attempts.
  8. Conduct Regular Security Assessments
    • Perform vulnerability assessments to identify potential risks.
    • Regularly review device configurations to ensure compliance with security policies.

 

Revision History:

VERSION DESCRIPTION RELEASE DATE
1.0 First release October 2, 2026

Relevant Products

MGate 5101-PBM-MN Series · MGate 5102-PBM-PN Series · MGate 5103 Series · MGate 5105-MB-EIP Series · MGate 5109 Series · MGate 5111 Series · MGate 5114 Series · MGate 5118 Series · MGate 5119 Series · MGate 5216 Series · MGate 5217 Series · MGate EIP3170/EIP3270 Series · MGate MB3170/MB3270 Series · MGate MB3180/MB3280/MB3480 Series · MGate MB3660 Series · MGate W5108/W5208 Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag
You have some items waiting in your bag; click here to finish your quote!
Feedback