CVE-2026-3868: Buffer Overflow
An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HTTPS management interface, an unauthenticated remote attacker could send specially crafted requests that trigger a buffer overflow condition, causing the web service to become unresponsive. Successful exploitation may result in a denial-of-service condition requiring a device reboot to restore normal operation. While successful exploitation can severely impact the availability of the affected device, no impact to the confidentiality or integrity of the affected product has been identified. Additionally, no confidentiality, integrity, or availability impact to the subsequent system has been identified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3868?
CVE-2026-3868 has been rated as a high-severity vulnerability due to its potential to allow unauthenticated remote exploitation.
How do I fix CVE-2026-3868?
To fix CVE-2026-3868, users should apply the latest firmware updates provided by Moxa for the Secure Router.
What impact does CVE-2026-3868 have on the Moxa Secure Router?
CVE-2026-3868 allows an attacker to execute arbitrary code through specially crafted HTTPS requests due to improper handling of length parameters.
Is CVE-2026-3868 a remote exploitation vulnerability?
Yes, CVE-2026-3868 can be exploited remotely without authentication, making it a significant security risk.
What type of vulnerability is CVE-2026-3868 classified as?
CVE-2026-3868 is classified as an improper handling of parameters vulnerability within the HTTPS management interface.