CVE Explorer
CVE-2026-3868
An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HTTPS management interface, an unauthenticated remote attacker could send specially crafted requests that trigger a buffer overflow condition, causing the web service to become unresponsive. Successful exploitation may result in a denial-of-service condition requiring a device reboot to restore normal operation. While suc
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"EDR-G9010 Series","vendor":"Moxa","versions":[{"lessThanOrEqual":"3.23.1","status":"affected","version":"1.0","versionType":"custom"},{"status":"unaffected","version":"3.24","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:587e49a6cb420a36702d9051f078001f2041de87ee4f5abf4084af825944c4f6 · sha256:de01e29e7225dc5a… · /containers/cna/affected/1
{"defaultStatus":"unaffected","product":"EDR-8010 Series","vendor":"Moxa","versions":[{"lessThanOrEqual":"3.23","status":"affected","version":"1.0","versionType":"custom"},{"status":"unaffected","version":"3.24","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:587e49a6cb420a36702d9051f078001f2041de87ee4f5abf4084af825944c4f6 · sha256:de01e29e7225dc5a… · /containers/cna/affected/0
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"EDR-G9010 Series","vendor":"Moxa","versions":[{"lessThanOrEqual":"3.23.1","status":"affected","version":"1.0","versionType":"custom"},{"status":"unaffected","version":"3.24","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:587e49a6cb420a36702d9051f078001f2041de87ee4f5abf4084af825944c4f6 · sha256:de01e29e7225dc5a… · /containers/cna/affected/1
{"defaultStatus":"unaffected","product":"EDR-8010 Series","vendor":"Moxa","versions":[{"lessThanOrEqual":"3.23","status":"affected","version":"1.0","versionType":"custom"},{"status":"unaffected","version":"3.24","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:587e49a6cb420a36702d9051f078001f2041de87ee4f5abf4084af825944c4f6 · sha256:de01e29e7225dc5a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:587e49a6cb420a36702d9051f078001f2041de87ee4f5abf4084af825944c4f6 · sha256:de01e29e7225dc5a… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-130","description":"CWE-130: Improper Handling of Length Parameter Inconsistency","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:587e49a6cb420a36702d9051f078001f2041de87ee4f5abf4084af825944c4f6 · sha256:de01e29e7225dc5a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://www.moxa.com/en/support/product-support/security-advisory/mpsa-261521-cve-2026-3867-cve-2026-3868-improper-ownership-management-and-improper-handling-of-length-parameter-incons"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:587e49a6cb420a36702d9051f078001f2041de87ee4f5abf4084af825944c4f6 · sha256:de01e29e7225dc5a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.