CVE-2015-6480: Moxa Oncell Central Manager
High severity, CVSS 8.3. EPSS: 1.8% chance of exploitation in the next 30 days.
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.
Affected products
- Moxa Oncell Central Manager: up to and including 2.0
Published 2015-12-21. Last modified 2026-06-17.