CVE-2019-6520: Moxa Eds-405a Firmware

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.

Affected products

  • Moxa Eds-405a Firmware: up to and including 3.8
  • Moxa Eds-408a Firmware: up to and including 3.8
  • Moxa Eds-510a Firmware: up to and including 3.8
  • Moxa Iks-g6824a Firmware: up to and including 4.5

Published 2019-03-05. Last modified 2026-06-17.