Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Remi Onno

#17378of 53,633
15.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-49653
6.9
2026-06-16
Moxa · Nport W2150A-W4/W2250A-W4 Series · CVE-2026-10828
A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections.
PT-2026-49654
8.6
2026-06-16
Moxa · Nport W2150A-W4/W2250A-W4 Series · CVE-2026-10829
A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input in the "Server location" parameter on the Basic settings page. An attacker could exploit this vulnerability by sending crafted input to the web service, resulting in memory corruption. Successful exploitation of this vulnerability could allow remote code execution on the target system with root privileges.