CVE-2026-3867 Details
Description
An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the hashed password of the administrative account. Successful exploitation of this vulnerability could allow an attacker to obtain sensitive information. Exploitation is only possible under a specific condition — when the configuration file has been exported. This vulnerability does not impact the integrity or availability of the affected product, and no confidentiality, integrity, or availability impact to the subsequent system has been identified.
A vulnerability has been identified in Moxa's Secure Router, related to improper ownership management. This issue allows a low-privileged authenticated user to access a configuration file that contains the hashed password of the administrative account. Exploitation of this vulnerability could lead to the unauthorized retrieval of sensitive information. However, this issue can only be exploited if the configuration file has been exported. The vulnerability does not affect the integrity or availability of the Secure Router, nor does it impact the confidentiality, integrity, or availability of any subsequent systems.
Users can update to firmware version 3.24 or later. For OnCell G4302-LTE4 Series and OnCell G4308-LTE4 Series, please contact Moxa Technical Support for the security patch (v3.24.1).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-282 | Improper Ownership Management | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | New CVE Received | [email protected] |