CVE-2023-39979: Moxa Mxsecurity

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

Affected products

  • Moxa Mxsecurity: before 1.1.0 (fixed in 1.1.0)

Published 2023-09-02. Last modified 2026-06-17.