Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.
Conclusion & alert: CVE-2026-0715 is rated Low Risk (32.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.22%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.02% | 0.22% | +0.20% |
| 2 | 2026-02-06 | — | 0.02% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.0 | 4.0 | HIGH |
|
— | — | [email protected] |
| 6.8 | 3.1 | MEDIUM |
|
0.9 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| moxa | uc-1222a_firmware | <= 1.4 | cpe:2.3:o:moxa:uc-1222a_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-2222a-t-us_firmware | <= 1.4 | cpe:2.3:o:moxa:uc-2222a-t-us_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-2222a-t_firmware | <= 1.4 | cpe:2.3:o:moxa:uc-2222a-t_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-2222a-t-ap_firmware | <= 1.4 | cpe:2.3:o:moxa:uc-2222a-t-ap_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-2222a-t-eu_firmware | <= 1.4 | cpe:2.3:o:moxa:uc-2222a-t-eu_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-3434a-t-lte-wifi_firmware | <= 1.2 | cpe:2.3:o:moxa:uc-3434a-t-lte-wifi_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-3424a-t-lte_firmware | <= 1.2 | cpe:2.3:o:moxa:uc-3424a-t-lte_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-3420a-t-lte_firmware | <= 1.2 | cpe:2.3:o:moxa:uc-3420a-t-lte_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-3430a-t-lte-wifi_firmware | <= 1.2 | cpe:2.3:o:moxa:uc-3430a-t-lte-wifi_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-4450a-t-5g_firmware | <= 1.3 | cpe:2.3:o:moxa:uc-4450a-t-5g_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-4434a-i-t_firmware | <= 1.3 | cpe:2.3:o:moxa:uc-4434a-i-t_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-4410a-t_firmware | <= 1.3 | cpe:2.3:o:moxa:uc-4410a-t_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-4454a-t-5g_firmware | <= 1.3 | cpe:2.3:o:moxa:uc-4454a-t-5g_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-4414a-i-t_firmware | <= 1.3 | cpe:2.3:o:moxa:uc-4414a-i-t_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-4430a-t_firmware | <= 1.3 | cpe:2.3:o:moxa:uc-4430a-t_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-8210-t-lx-s_firmware | <= 1.5 | cpe:2.3:o:moxa:uc-8210-t-lx-s_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-8220-t-lx-eu-s_firmware | <= 1.5 | cpe:2.3:o:moxa:uc-8220-t-lx-eu-s_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-8220-t-lx-ap-s_firmware | <= 1.5 | cpe:2.3:o:moxa:uc-8220-t-lx-ap-s_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-8220-t-lx-us-s_firmware | <= 1.5 | cpe:2.3:o:moxa:uc-8220-t-lx-us-s_firmware:*:*:*:*:*:*:*:* |
| moxa | uc-8220-t-lx_firmware | <= 1.5 | cpe:2.3:o:moxa:uc-8220-t-lx_firmware:*:*:*:*:*:*:*:* |
| moxa | v1202-ct-t_firmware | <= 1.2.0 | cpe:2.3:o:moxa:v1202-ct-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v1222-ct-t_firmware | <= 1.2.0 | cpe:2.3:o:moxa:v1222-ct-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v1222-w-ct-t_firmware | <= 1.2.0 | cpe:2.3:o:moxa:v1222-w-ct-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-kl7-ct-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-kl7-ct-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-kl7-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-kl7-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-wl7-ct-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-wl7-ct-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-wl5-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-wl5-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-kl1-ct-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-kl1-ct-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-wl3-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-wl3-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-wl1-ct-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-wl1-ct-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-kl3-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-kl3-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-wl1-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-wl1-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-kl1-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-kl1-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-wl7-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-wl7-t_firmware:*:*:*:*:*:*:*:* |
| moxa | v2406c-kl5-t_firmware | <= 1.2 | cpe:2.3:o:moxa:v2406c-kl5-t_firmware:*:*:*:*:*:*:*:* |