A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

Project Subscriptions

Vendors Products
Mgate Mb3170 Series Subscribe
Mgate Mb3270 Series Subscribe
Advisories

No advisories yet.

Fixes

Solution

Moxa has developed appropriate solutions to address the vulnerability: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-269540-cve-2026-86325,-cve-2026-86326-two-vulnerabilities-in-protocol-gateways


Workaround

No workaround given by the vendor.

History

Fri, 02 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.
First Time appeared Moxa
Moxa mgate Mb3170 Series
Moxa mgate Mb3270 Series
Weaknesses CWE-121
CPEs cpe:2.3:a:moxa:mgate_mb3170_series:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:mgate_mb3270_series:*:*:*:*:*:*:*:*
Vendors & Products Moxa
Moxa mgate Mb3170 Series
Moxa mgate Mb3270 Series
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published:

Updated: 2026-10-02T10:49:43.686Z

Reserved: 2026-09-07T06:34:02.910Z

Link: CVE-2026-86325

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses