Moxa NPort IAW5000A-I/O Series Serial Device Server Improper Input Validation
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 2.7%
exploitation probability
2.7%top 16% of all CVEs
observed exploitation
nono source reports it
In short
The Moxa NPort IAW5000A-I/O serial device server fails to properly check user input on its web interface, allowing remote attackers to run unauthorized commands on the device.
Technical detail
The built-in web server in Moxa NPort IAW5000A-I/O firmware ≤2.2 lacks proper input validation (CWE-20), enabling unauthenticated remote command execution via malicious web requests without requiring prior network access or credentials.
Summary generated and translated by AI from the official description.
Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Moxa · NPort IAW5000A-I/O series firmware