CVE-2026-0715Disclosure(moxa / uc-1222a)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • uc-1222a
  • uc-1222a_firmware
  • uc-2222a-t
  • uc-2222a-t-ap

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
uc-1222auc-1222a_firmwareuc-2222a-tuc-2222a-t-apuc-2222a-t-ap_firmwareuc-2222a-t-euuc-2222a-t-eu_firmwareuc-2222a-t-usuc-2222a-t-us_firmwareuc-2222a-t_firmware

1 version affected across 70 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-05: 1Technical Details · 2026-02-05: 102-05
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-0715 Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical acces… https://www.cve.org/CVERecord?id=CVE-2026-0715

    Post summary

    The post announces CVE-2026-0715, noting that Moxa Arm-based industrial computers use a device-unique bootloader password, implying a vulnerability related to physical access. No PoC, exploit code, or patch details are provided.

    00010119
    56.5K followersView on X
CPE platform detail70 entries

70 of 70 entries

PartVendorProductVersionTarget SWTarget HW
HWmoxauc-1222a---
OSmoxauc-1222a_firmware---
HWmoxauc-2222a-t---
HWmoxauc-2222a-t-ap---
OSmoxauc-2222a-t-ap_firmware---
HWmoxauc-2222a-t-eu---
OSmoxauc-2222a-t-eu_firmware---
HWmoxauc-2222a-t-us---
OSmoxauc-2222a-t-us_firmware---
OSmoxauc-2222a-t_firmware---
HWmoxauc-3420a-t-lte---
OSmoxauc-3420a-t-lte_firmware---
HWmoxauc-3424a-t-lte---
OSmoxauc-3424a-t-lte_firmware---
HWmoxauc-3430a-t-lte-wifi---
OSmoxauc-3430a-t-lte-wifi_firmware---
HWmoxauc-3434a-t-lte-wifi---
OSmoxauc-3434a-t-lte-wifi_firmware---
HWmoxauc-4410a-t---
OSmoxauc-4410a-t_firmware---
HWmoxauc-4414a-i-t---
OSmoxauc-4414a-i-t_firmware---
HWmoxauc-4430a-t---
OSmoxauc-4430a-t_firmware---
HWmoxauc-4434a-i-t---
OSmoxauc-4434a-i-t_firmware---
HWmoxauc-4450a-t-5g---
OSmoxauc-4450a-t-5g_firmware---
HWmoxauc-4454a-t-5g---
OSmoxauc-4454a-t-5g_firmware---
HWmoxauc-8210-t-lx-s---
OSmoxauc-8210-t-lx-s_firmware---
HWmoxauc-8220-t-lx---
HWmoxauc-8220-t-lx-ap-s---
OSmoxauc-8220-t-lx-ap-s_firmware---
HWmoxauc-8220-t-lx-eu-s---
OSmoxauc-8220-t-lx-eu-s_firmware---
HWmoxauc-8220-t-lx-us-s---
OSmoxauc-8220-t-lx-us-s_firmware---
OSmoxauc-8220-t-lx_firmware---
HWmoxav1202-ct-t---
OSmoxav1202-ct-t_firmware---
HWmoxav1222-ct-t---
OSmoxav1222-ct-t_firmware---
HWmoxav1222-w-ct-t---
OSmoxav1222-w-ct-t_firmware---
HWmoxav2406c-kl1-ct-t---
OSmoxav2406c-kl1-ct-t_firmware---
HWmoxav2406c-kl1-t---
OSmoxav2406c-kl1-t_firmware---
HWmoxav2406c-kl3-t---
OSmoxav2406c-kl3-t_firmware---
HWmoxav2406c-kl5-t---
OSmoxav2406c-kl5-t_firmware---
HWmoxav2406c-kl7-ct-t---
OSmoxav2406c-kl7-ct-t_firmware---
HWmoxav2406c-kl7-t---
OSmoxav2406c-kl7-t_firmware---
HWmoxav2406c-wl1-ct-t---
OSmoxav2406c-wl1-ct-t_firmware---
HWmoxav2406c-wl1-t---
OSmoxav2406c-wl1-t_firmware---
HWmoxav2406c-wl3-t---
OSmoxav2406c-wl3-t_firmware---
HWmoxav2406c-wl5-t---
OSmoxav2406c-wl5-t_firmware---
HWmoxav2406c-wl7-ct-t---
OSmoxav2406c-wl7-ct-t_firmware---
HWmoxav2406c-wl7-t---
OSmoxav2406c-wl7-t_firmware---

Explore more