CVE-2026-0715 Details
Description
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.
A vulnerability exists in Moxa Arm-based industrial computers running Moxa Industrial Linux Secure, which use a device-unique bootloader password. An attacker with physical access to the device could use this password to access the bootloader menu via a serial interface. However, this access does not allow full system takeover or privilege escalation, as the bootloader only permits flashing of Moxa-signed images. While malicious firmware cannot be installed or arbitrary code executed, accessing the bootloader could lead to a temporary denial-of-service condition if a valid image is reflashed.
Users are advised to change the bootloader default password. For specific guidance, refer to the 'Moxa Industrial Linux 3.x (Debian 11) Arm-based Computers Manual (with Security Hardening Guide)' version 3.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| moxa uc-1222a firmware | <= 1.4 |
CPE
Remediation
| |
| moxa uc-1222a | All versions |
CPE
Remediation
| |
| moxa uc-2222a-t-us firmware | <= 1.4 |
CPE
Remediation
| |
| moxa uc-2222a-t-us | All versions |
CPE
Remediation
| |
| moxa uc-2222a-t firmware | <= 1.4 |
CPE
Remediation
| |
| moxa uc-2222a-t | All versions |
CPE
Remediation
| |
| moxa uc-2222a-t-ap firmware | <= 1.4 |
CPE
Remediation
| |
| moxa uc-2222a-t-ap | All versions |
CPE
Remediation
| |
| moxa uc-2222a-t-eu firmware | <= 1.4 |
CPE
Remediation
| |
| moxa uc-2222a-t-eu | All versions |
CPE
Remediation
| |
| moxa uc-3434a-t-lte-wifi firmware | <= 1.2 |
CPE
Remediation
| |
| moxa uc-3434a-t-lte-wifi | All versions |
CPE
Remediation
| |
| moxa uc-3424a-t-lte firmware | <= 1.2 |
CPE
Remediation
| |
| moxa uc-3424a-t-lte | All versions |
CPE
Remediation
| |
| moxa uc-3420a-t-lte firmware | <= 1.2 |
CPE
Remediation
| |
| moxa uc-3420a-t-lte | All versions |
CPE
Remediation
| |
| moxa uc-3430a-t-lte-wifi firmware | <= 1.2 |
CPE
Remediation
| |
| moxa uc-3430a-t-lte-wifi | All versions |
CPE
Remediation
| |
| moxa uc-4450a-t-5g firmware | <= 1.3 |
CPE
Remediation
| |
| moxa uc-4450a-t-5g | All versions |
CPE
Remediation
| |
| moxa uc-4434a-i-t firmware | <= 1.3 |
CPE
Remediation
| |
| moxa uc-4434a-i-t | All versions |
CPE
Remediation
| |
| moxa uc-4410a-t firmware | <= 1.3 |
CPE
Remediation
| |
| moxa uc-4410a-t | All versions |
CPE
Remediation
| |
| moxa uc-4454a-t-5g firmware | <= 1.3 |
CPE
Remediation
| |
| moxa uc-4454a-t-5g | All versions |
CPE
Remediation
| |
| moxa uc-4414a-i-t firmware | <= 1.3 |
CPE
Remediation
| |
| moxa uc-4414a-i-t | All versions |
CPE
Remediation
| |
| moxa uc-4430a-t firmware | <= 1.3 |
CPE
Remediation
| |
| moxa uc-4430a-t | All versions |
CPE
Remediation
| |
| moxa uc-8210-t-lx-s firmware | <= 1.5 |
CPE
Remediation
| |
| moxa uc-8210-t-lx-s | All versions |
CPE
Remediation
| |
| moxa uc-8220-t-lx-eu-s firmware | <= 1.5 |
CPE
Remediation
| |
| moxa uc-8220-t-lx-eu-s | All versions |
CPE
Remediation
| |
| moxa uc-8220-t-lx-ap-s firmware | <= 1.5 |
CPE
Remediation
| |
| moxa uc-8220-t-lx-ap-s | All versions |
CPE
Remediation
| |
| moxa uc-8220-t-lx-us-s firmware | <= 1.5 |
CPE
Remediation
| |
| moxa uc-8220-t-lx-us-s | All versions |
CPE
Remediation
| |
| moxa uc-8220-t-lx firmware | <= 1.5 |
CPE
Remediation
| |
| moxa uc-8220-t-lx | All versions |
CPE
Remediation
| |
| moxa v1202-ct-t firmware | <= 1.2.0 |
CPE
Remediation
| |
| moxa v1202-ct-t | All versions |
CPE
Remediation
| |
| moxa v1222-ct-t firmware | <= 1.2.0 |
CPE
Remediation
| |
| moxa v1222-ct-t | All versions |
CPE
Remediation
| |
| moxa v1222-w-ct-t firmware | <= 1.2.0 |
CPE
Remediation
| |
| moxa v1222-w-ct-t | All versions |
CPE
Remediation
| |
| moxa v2406c-kl7-ct-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-kl7-ct-t | All versions |
CPE
Remediation
| |
| moxa v2406c-kl7-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-kl7-t | All versions |
CPE
Remediation
| |
| moxa v2406c-wl7-ct-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-wl7-ct-t | All versions |
CPE
Remediation
| |
| moxa v2406c-wl5-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-wl5-t | All versions |
CPE
Remediation
| |
| moxa v2406c-kl1-ct-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-kl1-ct-t | All versions |
CPE
Remediation
| |
| moxa v2406c-wl3-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-wl3-t | All versions |
CPE
Remediation
| |
| moxa v2406c-wl1-ct-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-wl1-ct-t | All versions |
CPE
Remediation
| |
| moxa v2406c-kl3-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-kl3-t | All versions |
CPE
Remediation
| |
| moxa v2406c-wl1-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-wl1-t | All versions |
CPE
Remediation
| |
| moxa v2406c-kl1-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-kl1-t | All versions |
CPE
Remediation
| |
| moxa v2406c-wl7-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-wl7-t | All versions |
CPE
Remediation
| |
| moxa v2406c-kl5-t firmware | <= 1.2 |
CPE
Remediation
| |
| moxa v2406c-kl5-t | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 18, 2026 | Initial Analysis | [email protected] |
| Feb 5, 2026 | New CVE Received | [email protected] |