CVE Explorer
CVE-2026-9266
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the devi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["OS image (MIL3 Secure version)"],"product":"UC-1200A Series","vendor":"Moxa","versions":[{"lessThanOrEqual":"1.4","status":"affected","version":"1.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1d3963846c87ca2791b7777f72abc1f2eb0aa01baba8cdf3d6f11642213a5bde · sha256:0d62cc2e424c4c9b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"PHYSICAL","baseScore":7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"H…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1d3963846c87ca2791b7777f72abc1f2eb0aa01baba8cdf3d6f11642213a5bde · sha256:0d62cc2e424c4c9b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-325","description":"CWE-325: Missing Cryptographic Step","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1d3963846c87ca2791b7777f72abc1f2eb0aa01baba8cdf3d6f11642213a5bde · sha256:0d62cc2e424c4c9b… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://www.moxa.com/en/support/product-support/security-advisory/mpsa-266240-cve-2026-9266-missing-required-cryptographic-step-vulnerability-in-industrial-computers"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1d3963846c87ca2791b7777f72abc1f2eb0aa01baba8cdf3d6f11642213a5bde · sha256:0d62cc2e424c4c9b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.