CVE-2020-27149: Moxa Nport IA5150A Firmware

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration changed.

Affected products

  • Moxa Nport IA5150A Firmware: before 1.5 (fixed in 1.5)
  • Moxa Nport IA5250A Firmware: before 1.5 (fixed in 1.5)
  • Moxa Nport IA5450A Firmware: before 2.0 (fixed in 2.0)

Published 2021-05-14. Last modified 2026-06-17.