🔐 CVE Alert

CVE-2026-86325

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

CWE CWE-121
Vendor moxa
Product mgate mb3170 series
Published Oct 2, 2026
Last Updated Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for moxa mgate mb3170 series

Be the first to know when new unknown vulnerabilities affecting moxa mgate mb3170 series are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Moxa / MGate MB3170 Series
1.0 ≤ 4.7
Moxa / MGate MB3270 Series
1.0 ≤ 4.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
moxa.com: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-269540-cve-2026-86325,-cve-2026-86326-two-vulnerabilities-in-protocol-gateways