CVE-2026-0715

HIGHCVSS 7/10EPSS 0.22%

Last modified

CVE-2026-0715 is a high-severity vulnerability rated 7/10 on the CVSS scale. Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. EPSS estimates a 0.22% chance of exploitation in the next 30 days.

Description

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 4.0
7/10

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.22%

12.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MoxaUc-1222a Firmware<= 1.4
MoxaUc-2222a-T-Us Firmware<= 1.4
MoxaUc-2222a-T Firmware<= 1.4
MoxaUc-2222a-T-Ap Firmware<= 1.4
MoxaUc-2222a-T-Eu Firmware<= 1.4
MoxaUc-3434a-T-Lte-Wifi Firmware<= 1.2
MoxaUc-3424a-T-Lte Firmware<= 1.2
MoxaUc-3420a-T-Lte Firmware<= 1.2
MoxaUc-3430a-T-Lte-Wifi Firmware<= 1.2
MoxaUc-4450a-T-5g Firmware<= 1.3
MoxaUc-4434a-I-T Firmware<= 1.3
MoxaUc-4410a-T Firmware<= 1.3
MoxaUc-4454a-T-5g Firmware<= 1.3
MoxaUc-4414a-I-T Firmware<= 1.3
MoxaUc-4430a-T Firmware<= 1.3
MoxaUc-8210-T-Lx-S Firmware<= 1.5
MoxaUc-8220-T-Lx-Eu-S Firmware<= 1.5
MoxaUc-8220-T-Lx-Ap-S Firmware<= 1.5
MoxaUc-8220-T-Lx-Us-S Firmware<= 1.5
MoxaUc-8220-T-Lx Firmware<= 1.5
MoxaV1202-Ct-T Firmware<= 1.2.0
MoxaV1222-Ct-T Firmware<= 1.2.0
MoxaV1222-W-Ct-T Firmware<= 1.2.0
MoxaV2406c-Kl7-Ct-T Firmware<= 1.2
MoxaV2406c-Kl7-T Firmware<= 1.2
MoxaV2406c-Wl7-Ct-T Firmware<= 1.2
MoxaV2406c-Wl5-T Firmware<= 1.2
MoxaV2406c-Kl1-Ct-T Firmware<= 1.2
MoxaV2406c-Wl3-T Firmware<= 1.2
MoxaV2406c-Wl1-Ct-T Firmware<= 1.2
MoxaV2406c-Kl3-T Firmware<= 1.2
MoxaV2406c-Wl1-T Firmware<= 1.2
MoxaV2406c-Kl1-T Firmware<= 1.2
MoxaV2406c-Wl7-T Firmware<= 1.2
MoxaV2406c-Kl5-T Firmware<= 1.2

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-0715?
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.
How severe is CVE-2026-0715?
CVE-2026-0715 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2026-0715?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2026-0715?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST