CVE-2019-6524: Moxa Eds-405a Firmware

Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.

Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.

Affected products

  • Moxa Eds-405a Firmware: up to and including 3.8
  • Moxa Eds-408a Firmware: up to and including 3.8
  • Moxa Eds-510a Firmware: up to and including 3.8
  • Moxa Iks-g6824a Firmware: up to and including 4.5

Published 2019-03-05. Last modified 2026-06-17.