TL;DR
Moxa disclosed two Moxa MGate vulnerabilities on October 2, 2026. The worse flaw, CVE-2026-86325, scores 9.4 on CVSS 4.0 and lets a read-only user corrupt device memory. The second, CVE-2026-86326, lets a privileged attacker install tampered firmware.
- Product: Moxa MGate MB3170 Series
- Vulnerabilities: 2 flaws (CVE-2026-86325, CVE-2026-86326)
- Highest severity: 9.4 (Critical · CVSSv4)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv4) | Status |
|---|---|---|
| CVE-2026-86325 | 9.4 | Not exploited |
| CVE-2026-86326 | 8.6 | Not exploited |
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
MGate protocol gateways link serial and Ethernet devices in industrial networks. According to a 2016 CISA advisory, Moxa estimates these units run across energy, water, manufacturing, and government sectors. Moxa also urges fast action: “Given the high severity of these issues, users should apply the solutions immediately to reduce security risks.”
So far, no public proof-of-concept or in-the-wild exploitation has been confirmed. In addition, neither flaw appears in the CISA KEV catalog.
How the Attacks Work
CVE-2026-86325: Stack-Based Buffer Overflow
This bug sits in the account management interface. Moxa traces it to “insufficient length validation of the account_name parameter.” An overlong account name overflows a stack buffer. As a result, an attacker could read credentials from memory, alter memory, or crash the device.
CVE-2026-86326: Missing Firmware Signature Check
This flaw requires high privileges. Per the advisory, the device “does not properly verify the cryptographic authenticity of firmware images before installation.” Consequently, a modified image could run unauthorized code and persist across later updates.
Affected Versions
CVE-2026-86325 hits these firmware releases:
- MGate MB3170 and MB3270 Series: v4.7 and earlier
- MGate MB3180 Series: v2.7 and earlier
- MGate MB3280 Series: v4.6 and earlier
- MGate MB3480 Series: v4.5 and earlier
- MGate MB3660 Series: v3.4 and earlier
- MGate 5217 Series: v1.5 and earlier
Meanwhile, CVE-2026-86326 affects all firmware versions across the MGate MB3000, EIP3000, and 5000 lines. The phased-out W5108/W5208 Series is also affected.
Patches and Mitigation
To fix CVE-2026-86325, upgrade to MB3170/MB3270 v4.7.1, MB3180 v2.7.1, MB3280 v4.6.3, MB3480 v4.5.1, MB3660 v3.4.5, or 5217 v1.5.5. However, no firmware fix exists yet for CVE-2026-86326. Instead, Moxa points users to its Security Hardening Guides for obtaining firmware only from official sources. Restricting access to management interfaces also cuts exposure to both Moxa MGate vulnerabilities.
Full details appear in Moxa security advisory MPSA-269540.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!