Moxa NPort 6100-G2/6200-G2 Series Execution with Unnecessary Privileges Vulnerability

Vulnerability

A vulnerability allowing execution with unnecessary privileges has been identified in the Moxa NPort 6100-G2/6200-G2 Series. This vulnerability allows an authenticated user with read-only access to make unauthorized configuration changes using the Moxa CLI Configuration (MCC) tool. The issue can be exploited remotely over the network, with low attack complexity and no user interaction required, but it does depend on specific system conditions or configurations. Successful exploitation could lead to unintended changes in device settings for the affected user role, potentially causing significant disruption to the device's normal operations. No impact on other systems has been reported.

Impact

Exploitation of this vulnerability could allow unauthorized configuration changes to be made by users with read-only access, potentially disrupting the device's normal operations and causing a temporary denial-of-service condition.

Remediation

Users are advised to contact Moxa Technical Support for the security patch (version 1.1.0) to address this vulnerability.

Added: Dec 31, 2025, 8:18 AM
Updated: Dec 31, 2025, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
4.5
remediation
7.9
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.