CVE-2026-0714Disclosure(moxa / uc-1222a)

LOWCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch moxa uc-1222a systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or opportunistic physical access and requires extended physical access, possession of the device, appropriate equipment, and sufficient time for signal capture and analysis. Remote exploitation is not possible.

2.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • uc-1222a
  • uc-1222a_firmware
  • uc-2222a-t
  • uc-2222a-t-ap

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 3 mentions (2026-02-19); latest day: 1
  • 14 total mentions across 9 days

Affected systems

Vendors
Products
uc-1222auc-1222a_firmwareuc-2222a-tuc-2222a-t-apuc-2222a-t-ap_firmwareuc-2222a-t-euuc-2222a-t-eu_firmwareuc-2222a-t-usuc-2222a-t-us_firmwareuc-2222a-t_firmware

1 version affected across 70 products

Deep dive

Activity timeline14 mentions / 9d
01223Mentions · 2026-02-05: 1Mentions · 2026-02-19: 3Mentions · 2026-02-20: 2Mentions · 2026-02-24: 3Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-03-02: 1Mentions · 2026-03-16: 1Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-02-24: 1PoC Mentioned / Linked · 2026-03-22: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-22: 102-0502-1902-2002-2402-2502-2703-0203-1603-22
Signal classification4 categories
Disclosure
857.1%
PoC
321.4%
General
214.3%
Patch
17.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-051
Disclosure1
2026-02-193
Disclosure2PoC1
2026-02-202
Disclosure1General1
2026-02-243
Disclosure1General1PoC1
2026-02-251
Disclosure1
2026-02-271
Disclosure1
2026-03-021
Patch1
2026-03-161
Disclosure1
2026-03-221
PoC1
Full discourse14 posts
  • 0xor0ne@0xor0ne
    PoC

    LUKS key extracted via passive SPI bus sniffing between SoC and TPM 2.0 (Moxa UC-1222A) (CVE-2026-0714) https://cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device #infosec https://t.co/fQvEVV15n6

    Post summary

    The tweet announces that researchers demonstrated how an attacker can passively sniff the SPI bus between SoC and TPM 2.0 on the Moxa UC-1222A to extract LUKS keys, as detailed in the linked CVE-2026-0714 report.

    250120911012.0K
    88.9K followersView on X
  • Sébastien Dudek 📡@FlUxIuS
    Disclosure

    [CVE-2026-0714] TPM-sniffing LUKS Keys on an Embedded Device: https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device

    Post summary

    The text announces the disclosure of CVE-2026-0714, a vulnerability that allows TPM sniffing to recover LUKS keys on an embedded device, with a research link for details.

    1301981.3K
    3.7K followersView on X
  • Sébastien Dudek 📡@FlUxIuS
    Disclosure

    🔓 Great discussion on our community around CVE-2026-0714: TPM-sniffing LUKS keys on an embedded device via SPI bus. First documented attack using TPM2_NV_Read instead of Unseal. Join the thread 👇 https://community.penthertz.com/t/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device/12

    Post summary

    The post announces a discussion about CVE-2026-0714, detailing a TPM-based attack that sniffs LUKS keys via SPI, but does not provide PoC, exploit code, or patch information.

    0501691.1K
    3.9K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    TPMに対する盗聴攻撃によりLinuxのディスク暗号化LUKSの鍵を抽出できた。Cyloq社報告。ARMの産業用コンピュータMoxa UC-1222A Secure Editionが対象。鍵をSPIを平文で通過するためピンから傍受可能。CVE-2026-0714。 https://securityonline.info/first-ever-tpm-sniffing-attack-extracts-luks-keys-from-industrial-linux-devices/

    Post summary

    A TPM sniffing attack was demonstrated that extracts LUKS keys from industrial Linux devices, revealing CVE‑2026‑0714.

    0901151.5K
    7.2K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    [CVE-2026-0714] TPM-sniffing LUKS Keys on an Embedded Device https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device

    Post summary

    The linked article announces CVE‑2026‑0714, detailing a TPM‑sniffing technique that can retrieve LUKS keys on embedded devices, but does not mention PoC code, active exploitation, or remediation.

    0301421.1K
    55.6K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    [CVE-2026-0714] TPM-sniffing LUKS Keys on an Embedded Device https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device

    Post summary

    The article announces a TPM sniffing vulnerability that could expose LUKS keys on embedded devices, but it offers no evidence of active exploitation or available mitigations.

    051103962
    32.6K followersView on X
  • suzaki@KuniSuzaki
    Patch

    SPIバスからのTPM鍵漏洩の実例。 [CVE-2026-0714] TPM-sniffing LUKS Keys on an Embedded Device https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device この記事にもあるが、parameter encryptionが対策としてある。文書も。 CPU to TPM Bus Protection Guidance – Passive Attack Mitigation https://trustedcomputinggroup.org/wp-content/uploads/TCG_CPU_TPM_Bus_Protection_Guidance_Passive_Attack_Mitigation_8May23-3.pdf 残念ながらparameter encryptionがきちんと使われている事例を知らない。

    Post summary

    The post highlights the TPM key leakage vulnerability CVE‑2026‑0714, cites a research article and mitigation guidance, but does not mention a PoC or active exploitation.

    030841.1K
    2.1K followersView on X
  • Hardened-GNU/Linux@hardenedlinux
    General

    https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device

    Post summary

    The provided link does not offer clear evidence of any of the specific indicators; hence the content is classified as general mention with low confidence.

    02022247
    1.8K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Researchers extract LUKS decryption keys in plaintext from Moxa UC-1222A devices via a novel TPM bus sniffing attack (CVE-2026-0714). Secure your hardware. #TPMSniffing #HardwareSecurity #CyberSecurity #CVE20260714 #LinuxSecurity #LUKS #InfoSec #Moxa https://securityonline.info/first-ever-tpm-sniffing-attack-extracts-luks-keys-from-industrial-linux-devices/

    Post summary

    Researchers disclosed a TPM bus sniffing vulnerability (CVE-2026-0714) that allows attackers to extract LUKS keys in plaintext from Moxa UC-1222A industrial Linux devices.

    10010406
    10.4K followersView on X
  • Pietro Tedeschi@pietrotedeschi_
    PoC

    By passively monitoring the SPI bus between the SoC and the discrete TPM 2.0 device, the LUKS decryption key can be recovered @ https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device

    Post summary

    The post links to a PoC demonstrating how CVE‑2026‑0714 allows passive SPI bus sniffing to capture LUKS keys on an embedded device. No active exploitation, patch info, or false‑positive claim is present.

    0001041
    21 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0714 A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TP… https://www.cve.org/CVERecord?id=CVE-2026-0714

    Post summary

    A physical attack vulnerability has been disclosed for Moxa Industrial Linux 3 devices that use TPM‑backed LUKS full‑disk encryption.

    00010145
    56.5K followersView on X
  • Angsuman Chakraborty ✪@angsuman
    Disclosure

    TPM-Sniffing LUKS Keys on an Embedded Linux Device [CVE-2026-0714] https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device

    Post summary

    The text references a research article describing CVE‑2026‑0714, which allows attackers to sniff TPM and retrieve LUKS keys on embedded Linux devices; it lacks PoC, exploit details, patches, or evidence of active exploitation.

    0000053
    7.5K followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2026-0714 from https://vulntracker.io/cves/CVE-2026-0714

    Post summary

    The tweet merely directs readers to a link for more information on CVE-2026-0714, without offering additional context or claims.

    0000064
    336 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    [CVE-2026-0714] TPM-sniffing LUKS Keys on an Embedded Device https://www.cyloq.se/en/research/cve-2026-0714-tpm-sniffing-luks-keys-on-an-embedded-device https://t.co/LcX195dIln

    Post summary

    The tweet announces the discovery of CVE-2026-0714, a vulnerability allowing TPM sniffing to extract LUKS keys on embedded devices, and points to a research article for further details.

    0000060
    382 followersView on X
CPE platform detail70 entries

70 of 70 entries

PartVendorProductVersionTarget SWTarget HW
HWmoxauc-1222a---
OSmoxauc-1222a_firmware---
HWmoxauc-2222a-t---
HWmoxauc-2222a-t-ap---
OSmoxauc-2222a-t-ap_firmware---
HWmoxauc-2222a-t-eu---
OSmoxauc-2222a-t-eu_firmware---
HWmoxauc-2222a-t-us---
OSmoxauc-2222a-t-us_firmware---
OSmoxauc-2222a-t_firmware---
HWmoxauc-3420a-t-lte---
OSmoxauc-3420a-t-lte_firmware---
HWmoxauc-3424a-t-lte---
OSmoxauc-3424a-t-lte_firmware---
HWmoxauc-3430a-t-lte-wifi---
OSmoxauc-3430a-t-lte-wifi_firmware---
HWmoxauc-3434a-t-lte-wifi---
OSmoxauc-3434a-t-lte-wifi_firmware---
HWmoxauc-4410a-t---
OSmoxauc-4410a-t_firmware---
HWmoxauc-4414a-i-t---
OSmoxauc-4414a-i-t_firmware---
HWmoxauc-4430a-t---
OSmoxauc-4430a-t_firmware---
HWmoxauc-4434a-i-t---
OSmoxauc-4434a-i-t_firmware---
HWmoxauc-4450a-t-5g---
OSmoxauc-4450a-t-5g_firmware---
HWmoxauc-4454a-t-5g---
OSmoxauc-4454a-t-5g_firmware---
HWmoxauc-8210-t-lx-s---
OSmoxauc-8210-t-lx-s_firmware---
HWmoxauc-8220-t-lx---
HWmoxauc-8220-t-lx-ap-s---
OSmoxauc-8220-t-lx-ap-s_firmware---
HWmoxauc-8220-t-lx-eu-s---
OSmoxauc-8220-t-lx-eu-s_firmware---
HWmoxauc-8220-t-lx-us-s---
OSmoxauc-8220-t-lx-us-s_firmware---
OSmoxauc-8220-t-lx_firmware---
HWmoxav1202-ct-t---
OSmoxav1202-ct-t_firmware---
HWmoxav1222-ct-t---
OSmoxav1222-ct-t_firmware---
HWmoxav1222-w-ct-t---
OSmoxav1222-w-ct-t_firmware---
HWmoxav2406c-kl1-ct-t---
OSmoxav2406c-kl1-ct-t_firmware---
HWmoxav2406c-kl1-t---
OSmoxav2406c-kl1-t_firmware---
HWmoxav2406c-kl3-t---
OSmoxav2406c-kl3-t_firmware---
HWmoxav2406c-kl5-t---
OSmoxav2406c-kl5-t_firmware---
HWmoxav2406c-kl7-ct-t---
OSmoxav2406c-kl7-ct-t_firmware---
HWmoxav2406c-kl7-t---
OSmoxav2406c-kl7-t_firmware---
HWmoxav2406c-wl1-ct-t---
OSmoxav2406c-wl1-ct-t_firmware---
HWmoxav2406c-wl1-t---
OSmoxav2406c-wl1-t_firmware---
HWmoxav2406c-wl3-t---
OSmoxav2406c-wl3-t_firmware---
HWmoxav2406c-wl5-t---
OSmoxav2406c-wl5-t_firmware---
HWmoxav2406c-wl7-ct-t---
OSmoxav2406c-wl7-ct-t_firmware---
HWmoxav2406c-wl7-t---
OSmoxav2406c-wl7-t_firmware---

Explore more