CVE-2026-86326: High severity vulnerability
An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful exploitation could allow the attacker to execute unauthorized code, compromise the integrity and availability of the device, and persist malicious modifications across subsequent firmware updates.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Obtain firmware only from official Moxa sources and perform firmware updates securely in accordance with the applicable Security Hardening Guide for the MGate MB3000 or MGate 5000 Series.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs high privileges and access to the device's firmware update interface. This is not described as an unauthenticated or remote-only attack.
What could exploitation allow an attacker to do?
A successful attacker could install a crafted or modified firmware image and execute unauthorized code on the device. This could compromise device integrity and availability and allow malicious changes to persist through later firmware updates.