Moxa Uc-8220-T-Lx-Us-S Firmware vulnerabilities

5 known vulnerabilities affecting moxa/uc-8220-t-lx-us-s_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-0714HIGHCVSS 7.0≤ 1.52026-02-05
CVE-2026-0714 [HIGH] CWE-319 CVE-2026-0714: A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS fu A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM commu
nvd
CVE-2026-0715HIGHCVSS 7.0≤ 1.52026-02-05
CVE-2026-0715 [HIGH] CWE-522 CVE-2026-0715: Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloa Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. Access to the bootloader menu does not allow full system takeover or privilege escalation.
nvd
CVE-2023-1257MEDIUMCVSS 6.8≥ 1.0, ≤ 2.42023-03-07
CVE-2023-1257 [HIGH] CVE-2023-1257: An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of th An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.
nvd
CVE-2022-3086HIGHCVSS 7.6≥ 1.0, ≤ 2.42022-12-02
CVE-2022-3086 [HIGH] CWE-77 CVE-2022-3086: Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enab Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.
nvd
CVE-2022-3088HIGHCVSS 7.8≥ 1.0, ≤ 1.52022-11-28
CVE-2022-3088 [HIGH] CWE-250 CVE-2022-3088: UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC- UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v
nvd