A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections. | |
| First Time appeared |
Moxa
Moxa nport W2150a-w4 W2250a-w4 Series Moxa nport W2150a W2250a Series |
|
| Weaknesses | CWE-134 | |
| CPEs | cpe:2.3:a:moxa:nport_w2150a-w4_w2250a-w4_series:*:*:*:*:*:*:*:* cpe:2.3:a:moxa:nport_w2150a_w2250a_series:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Moxa
Moxa nport W2150a-w4 W2250a-w4 Series Moxa nport W2150a W2250a Series |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Moxa
Published:
Updated: 2026-06-16T12:20:06.556Z
Reserved: 2026-06-04T09:42:25.815Z
Link: CVE-2026-10828
Updated: 2026-06-16T12:20:00.512Z
Status : Awaiting Analysis
Published: 2026-06-16T12:16:24.920
Modified: 2026-06-16T15:26:04.250
Link: CVE-2026-10828
No data.
OpenCVE Enrichment
No data.