CVE-2024-12297: Moxa Eds-508a Series

Critical severity, CVSS 9.2. EPSS: 0.8% chance of exploitation in the next 30 days.

Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

Affected products

  • Moxa Eds-508a Series: from 1.0, up to and including 3.11
  • Moxa Pt-508 Series: from 1.0, up to and including 3.8
  • Moxa Pt-510 Series: from 1.0, up to and including 3.8
  • Moxa Pt-7528 Series: from 1.0, up to and including 5.0
  • Moxa Pt-7728 Series: from 1.0, up to and including 3.9
  • Moxa Pt-7828 Series: from 1.0, up to and including 4.0
  • Moxa Pt-g503 Series: from 1.0, up to and including 5.3
  • Moxa Pt-g510 Series: from 1.0, up to and including 6.5
  • Moxa Pt-g7728 Series: from 1.0, up to and including 6.5
  • Moxa Pt-g7828 Series: from 1.0, up to and including 6.5

Published 2025-01-15. Last modified 2026-06-17.