CVE-2026-3868Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HTTPS management interface, an unauthenticated remote attacker could send specially crafted requests that trigger a buffer overflow condition, causing the web service to become unresponsive. Successful exploitation may result in a denial-of-service condition requiring a device reboot to restore normal operation. While successful exploitation can severely impact the availability of the affected device, no impact to the confidentiality or integrity of the affected product has been identified. Additionally, no confidentiality, integrity, or availability impact to the subsequent system has been identified.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-27); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-27: 3Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 104-2704-28
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-273
Disclosure2General1
2026-04-281
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Info Disclosure & Buffer Overflow in Moxa #SecureRouter. #CVE-2026-3867 CVSS: 6.0 & #CVE-2026-3868 CVSS: 8.7. An auth user may access an exported config with the admin hash, while an unauth attacker can trigger reboot-required #DoS via HTTPS! #Patch #Patch #Patch

    Post summary

    Moxa SecureRouter is newly threatened by two CVEs (2026-3867 and 2026-3868) involving info disclosure, buffer overflow, and a reboot‑required DoS, with patches actively promoted.

    02000212
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3868 An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameter… https://www.cve.org/CVERecord?id=CVE-2026-3868

    Post summary

    The entry presents a brief disclosure of CVE‑2026‑3868, noting improper length‑parameter validation in Moxa’s Secure Router.

    0001097
    57.3K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3868 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3868 #CVE-2026-3868 #CVE #High #CyberSecurity #InfoSec https://t.co/L2Liatx8QA

    Post summary

    The tweet announces CVE-2026-3868, providing its severity score of 8.7 and a reference to the NVD entry, but offers no further technical, exploit, or mitigation information.

    0000049
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3868 Buffer Overflow Vulnerability in Moxa Secure Router HTTPS Management Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3868

    Post summary

    A new buffer overflow vulnerability (CVE‑2026‑3868) has been identified in the HTTPS management interface of Moxa Secure Router, but no exploitation or remediation details are provided.

    0000053
    4.0K followersView on X

Explore more