← All Advisories

Moxa TN-4500B Series Ethernet Switch Out-of-Bounds Write in Web Login Username Field Allows Remote Unauthenticated Attacker to Execute Code

Last refreshed2026-10-07

Status: UPDATED  |  Advisory ID: CVE-2026-15579

Key Details

CVECVE-2026-15579
CVSS Score / Version8.8 (High) / CVSS v4.0
Updated2026-09-18
Affected productsMoxa TN-4500B Series
Classified asCWE-787 (Out-of-bounds Write)
Exploitation prediction (EPSS)0.44% probability of exploitation in the next 30 days (36% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MoxaTN-4500B Series
SubsystemsGeneral OT
SectorsMultiple

What to Know

An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This may allow a remote attacker to submit a specially crafted overly long input, triggering a buffer overflow that can cause the authentication process to crash and result in a Denial of Service (DoS) attack. (NVD)

What to Do

Monitor Moxa's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-15579
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-15579