Impact
A stack-based buffer overflow exists in the account management interface of Moxa's protocol gateways. The flaw is triggered when the account_name parameter is not properly length‑checked, allowing an attacker with read‑only credentials to supply a crafted name that overflows an internal stack buffer. Successful exploitation can corrupt program execution, enabling the adversary to read sensitive device memory, modify arbitrary memory contents, and suspend device operation. The description states that exploitation could lead to disclosure of credentials and denial of service.
Affected Systems
Moxa MGate MB3170 Series and MGate MB3270 Series devices are affected. No specific firmware or software version information is provided beyond the product series. Only devices running the stated series are at risk.
Risk and Exploitability
The CVSS score of 9.4 categorizes this flaw as high severity, indicating that exploitation would grant significant control over the device. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack path is remote: an adversary authenticated as a read‑only user via the web management interface can send the malformed request from over the network. If the vulnerability is triggered, the attacker could execute arbitrary code with device privileges, leading to data leakage or service disruption.
OpenCVE Enrichment