CVE-2019-6563: Moxa Eds-405a Firmware

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.

Affected products

  • Moxa Eds-405a Firmware: up to and including 3.8
  • Moxa Eds-408a Firmware: up to and including 3.8
  • Moxa Eds-510a Firmware: up to and including 3.8
  • Moxa Iks-g6824a Firmware: up to and including 4.5

Published 2019-03-05. Last modified 2026-06-17.