CVE-2026-0714
published 2026-02-05CVE-2026-0714: A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the…
PriorityP431medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.11%
1.8th percentile
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or opportunistic physical access and requires extended physical access, possession of the device, appropriate equipment, and sufficient time for signal capture and analysis. Remote exploitation is not possible.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | uc-1200a_series | 1.0 – 1.4 | — |
| moxa | uc-1222a_firmware | <= 1.4 | — |
| moxa | uc-2222a-t-ap_firmware | <= 1.4 | — |
| moxa | uc-2222a-t-eu_firmware | <= 1.4 | — |
| moxa | uc-2222a-t-us_firmware | <= 1.4 | — |
| moxa | uc-2222a-t_firmware | <= 1.4 | — |
| moxa | uc-3420a-t-lte_firmware | <= 1.2 | — |
| moxa | uc-3424a-t-lte_firmware | <= 1.2 | — |
| moxa | uc-3430a-t-lte-wifi_firmware | <= 1.2 | — |
| moxa | uc-3434a-t-lte-wifi_firmware | <= 1.2 | — |
| moxa | uc-4410a-t_firmware | <= 1.3 | — |
| moxa | uc-4414a-i-t_firmware | <= 1.3 | — |
| moxa | uc-4430a-t_firmware | <= 1.3 | — |
| moxa | uc-4434a-i-t_firmware | <= 1.3 | — |
| moxa | uc-4450a-t-5g_firmware | <= 1.3 | — |
| moxa | uc-4454a-t-5g_firmware | <= 1.3 | — |
| moxa | uc-8210-t-lx-s_firmware | <= 1.5 | — |
| moxa | uc-8220-t-lx-ap-s_firmware | <= 1.5 | — |
| moxa | uc-8220-t-lx-eu-s_firmware | <= 1.5 | — |
| moxa | uc-8220-t-lx-us-s_firmware | <= 1.5 | — |
| moxa | uc-8220-t-lx_firmware | <= 1.5 | — |
| moxa | v1202-ct-t_firmware | <= 1.2.0 | — |
| moxa | v1222-ct-t_firmware | <= 1.2.0 | — |
| moxa | v1222-w-ct-t_firmware | <= 1.2.0 | — |
| moxa | v2406c-kl1-ct-t_firmware | <= 1.2 | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.0HIGHCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers.
ghsa_unreviewed·2026-06-12·CVSS 6.8
CVE-2026-9266 [MEDIUM] CWE-325 A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers.
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipm
GHSA
GHSA-jggw-c47g-3w3q: A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, whe
ghsa_unreviewed·2026-02-05
CVE-2026-0714 [HIGH] CWE-319 GHSA-jggw-c47g-3w3q: A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, whe
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or opportunistic physical access and requires extended physical access, possession of the device, appropriate equipment, and sufficient time for signal capture and analysis. Remote exploitation is not possible.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-02-05
Published