Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device
Published Feb 5, 2026
7.0
HIGHCVSS 4.0
EPSS 0.25%
Description
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.
Affected products
-
Affected
- ≥ 1.0, ≤ 1.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Moxa | UC-1200A Series | unaffected | Affected
|
Configuration 1
- ≤ 1.4
Configuration 2
- ≤ 1.4
Running on/with
- n/a
Configuration 3
- ≤ 1.4
Running on/with
- n/a
Configuration 4
- ≤ 1.4
Running on/with
- n/a
Configuration 5
- ≤ 1.4
Running on/with
- n/a
Configuration 6
- ≤ 1.2
Running on/with
- n/a
Configuration 7
- ≤ 1.2
Running on/with
- n/a
Configuration 8
- ≤ 1.2
Running on/with
- n/a
Configuration 9
- ≤ 1.2
Running on/with
- n/a
Configuration 10
- ≤ 1.3
Running on/with
- n/a
Configuration 11
- ≤ 1.3
Running on/with
- n/a
Configuration 12
- ≤ 1.3
Running on/with
- n/a
Configuration 13
- ≤ 1.3
Running on/with
- n/a
Configuration 14
- ≤ 1.3
Running on/with
- n/a
Configuration 15
- ≤ 1.3
Running on/with
- n/a
Configuration 16
- ≤ 1.5
Running on/with
- n/a
Configuration 17
- ≤ 1.5
Running on/with
- n/a
Configuration 18
- ≤ 1.5
Running on/with
- n/a
Configuration 19
- ≤ 1.5
Running on/with
- n/a
Configuration 20
- ≤ 1.5
Running on/with
- n/a
Configuration 21
- ≤ 1.2.0
Running on/with
- n/a
Configuration 22
- ≤ 1.2.0
Running on/with
- n/a
Configuration 23
- ≤ 1.2.0
Running on/with
- n/a
Configuration 24
- ≤ 1.2
Running on/with
- n/a
Configuration 25
- ≤ 1.2
Running on/with
- n/a
Configuration 26
- ≤ 1.2
Running on/with
- n/a
Configuration 27
- ≤ 1.2
Running on/with
- n/a
Configuration 28
- ≤ 1.2
Running on/with
- n/a
Configuration 29
- ≤ 1.2
Running on/with
- n/a
Configuration 30
- ≤ 1.2
Running on/with
- n/a
Configuration 31
- ≤ 1.2
Running on/with
- n/a
Configuration 32
- ≤ 1.2
Running on/with
- n/a
Configuration 33
- ≤ 1.2
Running on/with
- n/a
Configuration 34
- ≤ 1.2
Running on/with
- n/a
Configuration 35
- ≤ 1.2
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Refer to https://www.moxa.com/en/support/product-support/security-advisory/mpsa-255121-cve-2026-0714-cve-2026... https://www.moxa.com/en/support/product-support/security-advisory/mpsa-255121-cve-2026-0714-cve-2026-0715-multiple-vulnerabilities-in-industrial-computers
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5532 Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-255121-cve-2026-0714-cve-2026-0715-multiple-vulnerabilities-in-industrial-computers vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5532 | Advisory | |
| https://www.moxa.com/en/support/product-support/security-advisory/mpsa-255121-cve-2026-0714-cve-2026-0715-multiple-vulnerabilities-in-industrial-computers | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data