Skip to content
Threat Feed
medium advisory

Remote Denial of Service Vulnerability in Moxa TN-4500B Series

A critical out-of-bounds write vulnerability (CVE-2026-15579) in Moxa TN-4500B Series switches allows remote, unauthenticated attackers to cause a denial-of-service condition.

CVE search metadata

CVE search record: CVE-2026-15579. KEV: no. Product: TN-4500B Series (< 2.1). Brief: Remote Denial of Service Vulnerability in Moxa TN-4500B Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-moxa-dos/

Moxa has released security advisory MPSA-252620 detailing an out-of-bounds write vulnerability, identified as CVE-2026-15579, affecting the TN-4500B Series of industrial Ethernet switches. The vulnerability exists due to improper handling of input within the device's management interface. A remote, unauthenticated attacker can exploit this flaw by sending specially crafted packets to the affected hardware. Successful exploitation results in an immediate denial-of-service (DoS) condition, rendering the network switch unavailable and potentially disrupting critical industrial communication flows. All versions of the TN-4500B series prior to version 2.1 are affected.

Impact

The impact of this vulnerability is significant, as it permits the disruption of industrial network infrastructure from a remote, unauthenticated position. Organizations relying on the TN-4500B series for critical communications or SCADA operations face an increased risk of operational downtime and loss of visibility into the managed network segments if the device enters a crashed state.

Recommendation

Prioritize the immediate patching of all vulnerable Moxa TN-4500B series switches.

  • Upgrade all affected units to firmware version 2.1 or later as specified in Moxa Security Advisory MPSA-252620.
  • Restrict network access to the switch management interfaces using firewalls or ACLs to prevent unauthenticated remote access to the vulnerable service until patching is complete.

Mitigations

Upgrade firmware of all Moxa TN-4500B Series units to version 2.1 or later.

immediate IT Operations

CVE-2026-15579