Description

The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s web API. This may lead to an unexpected device reboot and result in a denial-of-service (DoS) condition. An authenticated remote attacker with web read-only privileges can exploit the vulnerable API to inject malicious input. Successful exploitation may cause the device to reboot, disrupting normal operations and causing a temporary denial of service.

INFO

Published Date :

2025-12-31T07:32:26.427Z

Last Modified :

2025-12-31T16:07:29.435Z

Source :

Moxa
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2026 vulnerability.

Vendors Products
Moxa
  • Nport 6100-g2 Series
  • Nport 6200-g2 Series
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-2026.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability