CVE-2026-10825: Moxa Nport 6000-g2 Series

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device reboot.

Affected products

  • Moxa Nport 6000-g2 Series: from 1.0, up to and including 1.1.0

Published 2026-06-16. Last modified 2026-06-17.