The factory's protocol translator will flash whatever firmware you hand it, signed or malicious, and the manufacturer says there is no fix coming
CVE-2026-86326 is a missing firmware signature verification flaw in Moxa's entire MGate protocol gateway family — the MB3000, EIP3000, 5000, and legacy W5000 series, spanning 17+ product lines across all firmware versions ever released. The device's firmware update mechanism does not validate cryptographic signatures before writing images to flash. An attacker who has already obtained admin-level access to the gateway's web management console can upload a trojanized firmware image that replaces the legitimate OS. The malicious image persists through reboots and — critically — survives subsequent legitimate firmware updates, giving the attacker a durable implant on a device that sits between your SCADA system and field PLCs/RTUs.
Moxa, acting as CNA, assigned a CVSS 4.0 score of 8.6 (HIGH) with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. That mechanical score is defensible: it correctly reflects the PR:H requirement (admin credentials needed) and the absence of downstream scope change. However, it does not account for two deployment realities that matter enormously. First, 100% of MGate installs sit in OT/ICS networks where the blast radius of a persistent gateway implant includes Modbus traffic manipulation and potential safety impact. Second, there is no patch and no timeline for one — the device was never designed with firmware signing, making this a design-level gap rather than a fixable bug. Our noisgate assessment lands at HIGH 8.4: the OT context and no-patch status push upward, while the PR:H prerequisite and typical OT segmentation provide real friction that prevents CRITICAL.
5 steps from start to impact.
Gain access to OT network segment
- Network connectivity to the OT VLAN or management subnet where the MGate is deployed
- IEC 62443 / Purdue Model segmentation should isolate OT management interfaces behind firewalls and jump hosts
- VPN + MFA policies on IT/OT boundary reduce reachability
Obtain admin credentials for MGate web console
admin/moxa or admin/admin) persist in a significant fraction of deployments, and shared credential usage is common. Credential theft from OT asset management databases or configuration backups is another vector.- Valid admin-level credentials for the MGate web console
- Knowledge of the device IP address and management port
- Organizations following Moxa's own hardening guide should have changed defaults
- RBAC-aware deployments may restrict firmware upload to a dedicated admin role
Navigate to firmware update interface
- Authenticated admin session on the MGate web console
- Session timeout and IP-based ACLs can limit the attack window
- HTTPS-only configurations (available on some models) prevent credential interception
Upload trojanized firmware image
- A crafted firmware image compatible with the target MGate hardware platform
- No firmware signature verification on the device (the vulnerability itself)
- Requires embedded systems expertise to build a working malicious firmware image
- Hardware-specific: different MGate series use different SoCs and boot processes
- No public PoC or weaponized tooling exists as of 2026-10-03
Persistent code execution on the gateway
- Successful firmware flash from step 4
- None — once flashed, the device runs the attacker's code unconditionally
- Firmware rollback/reinstall: Per Moxa advisory MPSA-269540, malicious firmware modifications persist across subsequent firmware updates. Reflashing with a legitimate image may not reliably overwrite a sophisticated implant that hooks the update mechanism itself. A full factory reset via serial console with hardware-verified boot media is the only reliable recovery path.
- Web application firewall (WAF): The firmware upload is a legitimate authenticated admin function over HTTP/HTTPS. A WAF cannot distinguish a malicious firmware upload from a legitimate one — the payload is an opaque binary blob.
- Endpoint detection / antivirus: MGate devices are embedded Linux/RTOS systems with no support for third-party security agents. There is no EDR, AV, or host-based detection capability available for these platforms.
- TLS/HTTPS enforcement alone: While HTTPS prevents credential interception in transit, it does not address the core vulnerability — the device accepts unsigned firmware regardless of transport security.
The supporting signals.
| In-the-wild exploitation | No known exploitation. Not listed in CISA KEV. No CISA ICS-CERT advisory issued yet for this specific CVE as of 2026-10-03. No campaigns attributed. |
|---|---|
| Proof-of-concept | No public PoC detected. Checked pocindex.io (no results), GitHub (no repos named CVE-2026-86326), ExploitDB (no entries), and nuclei templates (none). The SecureWithUmer/CVE-2026-PoCs aggregate repo does not list this CVE. Exploitation requires embedded firmware engineering skill, raising the bar for PoC development. |
| EPSS score | Not yet scored. FIRST EPSS API returns empty results — the CVE was published <24 hours ago (2026-10-02). Expect initial EPSS scoring within 7–14 days. Given PR:H and OT niche, anticipate a low EPSS probability (<5th percentile). |
| KEV status | Not listed. No CISA Known Exploited Vulnerabilities entry. No federal BOD deadline applies. |
| CVSS vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N — 8.6 HIGH (Moxa CNA-assigned, CVSS v4.0). Network-reachable but requires admin privileges. No scope change (compromised gateway only, per CVSS math — though real-world blast radius extends to downstream Modbus devices). |
| Affected versions | All firmware versions, all time across: MGate MB3170, MB3270, MB3180, MB3280, MB3480, MB3660, MB3000 series, EIP3170, EIP3270 (EIP3000 series), MGate 5217, 5105, 5109, 5101, 5114, 5118 (5000 series), and discontinued W5108/W5208. Version 1.0 through current. |
| Fixed versions | None. No firmware patch exists. Moxa advisory MPSA-269540 explicitly states no fix is available — the device was never designed with firmware signature verification. Moxa directs users to Security Hardening Guides. No timeline for a fix has been communicated. |
| Scanning / exposure | Shodan indexes ~4,400 Moxa devices globally (all product lines). MGate-specific exposure is a subset. OT protocol gateways should never be internet-exposed — most MGate management interfaces sit on internal OT VLANs. Internet exposure represents severe misconfiguration, not typical deployment. |
| Disclosure timeline | Reserved: 2026-09-07 · Published: 2026-10-02 · Advisory: MPSA-269540 (covers both CVE-2026-86325 and CVE-2026-86326) · NVD status: Awaiting Analysis |
| Reporter / credit | Self-reported by Moxa as CNA. No external researcher credited. Disclosed alongside CVE-2026-86325 (stack buffer overflow, CVSS 4.0 9.4 Critical) in the same advisory. |
Sources.
- Moxa Security Advisory MPSA-269540
- SecurityOnline — Moxa MGate Vulnerabilities Analysis
- Strix AI — CVE-2026-86326 Detail
- Threat Radar — CVE-2026-86326 Live Intelligence
- TheHackerWire — CVE-2026-86326 Vulnerability Details
- ThreatInt CVE Database — CVE-2026-86326
- Moxa MGate MB3170/MB3270 Series Product Page
- CISA ICS Advisory — Moxa MGate Protocol Gateways (historical)
Why this verdict
- PR:H is real friction but weaker than it looks in OT: Admin credentials on Moxa MGate devices are frequently default (
admin/moxa,admin/admin) or shared among operations staff. OT credential hygiene surveys consistently show 40–60% of embedded devices retain factory defaults. PR:H is a speed bump, not a wall. - No patch, no timeline — this is a design gap: The device never implemented firmware signing. Moxa's advisory offers no fix and no ETA. Defenders cannot remediate by patching; they can only mitigate by restricting access to the firmware update function. This durability of exposure pushes severity upward.
- Persistence survives remediation of the initial vector: Even if the initial compromise (stolen admin creds) is detected and credentials are rotated, the malicious firmware remains on the device. The implant outlives the incident response. This is qualitatively different from a configuration-based attack that can be reversed.
- Role multiplier: Moxa MGate gateways are purpose-built OT/ICS protocol translators — 100% of the installed base occupies the high-value OT role by definition. In canonical deployment (bridging SCADA HMI to field PLCs via Modbus RTU/TCP), a persistent firmware implant enables silent manipulation of process data: falsified sensor readings sent to operators, altered setpoints sent to PLCs, or total communication denial. This qualifies as OT-safety impact. The blast radius is per-gateway (host-level + downstream field devices), not fleet-scale — limiting the ceiling.
- No exploitation ecosystem yet: Zero PoC, zero KEV, zero observed campaigns. Exploitation requires embedded firmware reverse-engineering skill and hardware-specific knowledge. This caps the near-term probability, though it does not reduce the impact ceiling.
Why not higher?
CRITICAL would require that this vulnerability unlocks a new impact category beyond what the PR:H prerequisite already provides. An attacker with admin access to an MGate can already reconfigure Modbus slave/master routing, alter polling parameters, and manipulate data translation — achieving immediate (though non-persistent) safety impact through configuration alone. CVE-2026-86326's incremental contribution is persistence (surviving reboots and firmware updates), which is operationally significant but does not elevate the blast radius to fleet-scale, domain-scale, or supply-chain-scale. Additionally, the per-gateway blast radius (one gateway + its downstream serial devices) limits the scope versus a vulnerability in a centralized OT management platform. No PoC or weaponized tooling exists, and exploitation requires niche embedded systems expertise.
Why not lower?
MEDIUM would dangerously undercount the deployment context and the no-fix reality. These are exclusively OT/ICS devices where the affected function (firmware update) controls the entire device execution environment. The absence of any firmware signing is a permanent design gap — not a bug that will be patched in a release cycle. A persistent implant on a Modbus gateway that outlives credential rotation and standard IR playbooks represents a qualitative escalation in attacker dwell time. Combined with the consistently poor credential hygiene documented across OT embedded devices, the PR:H barrier is less protective than it would be in an IT context.
Crowdsourced verification payload.
Run from any workstation with network access to the MGate management interface. Requires Python 3.6+. No special privileges needed — the script makes unauthenticated HTTP requests to identify the device model. Example: python3 check_cve_2026_86326.py 192.168.127.254 or with custom port: python3 check_cve_2026_86326.py 10.0.100.10 8080. Exit code 1 = VULNERABLE, 0 = PATCHED (not an affected model), 2 = UNKNOWN.
#!/usr/bin/env python3
"""CVE-2026-86326 Checker - Moxa MGate Missing Firmware Signature Verification
All firmware versions of affected MGate series are vulnerable. No patch exists.
"""
import sys
import re
import urllib.request
import ssl
AFFECTED_KEYWORDS = [
"mb3170", "mb3270", "mb3180", "mb3280", "mb3480", "mb3660",
"mb3000", "eip3170", "eip3270", "eip3000",
"5217", "5105", "5109", "5101", "5114", "5118",
"w5108", "w5208", "mgate 5"
]
def check(host, port=80):
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
proto = "https" if port == 443 else "http"
url = f"{proto}://{host}:{port}/"
print(f"[*] Probing {url} ...")
try:
req = urllib.request.Request(url, headers={"User-Agent": "noisgate-CVE-2026-86326/1.0"})
with urllib.request.urlopen(req, timeout=15, context=ctx) as resp:
body = resp.read().decode("utf-8", errors="ignore")
headers = dict(resp.getheaders())
except Exception as e:
print(f"[!] Connection failed: {e}")
print("UNKNOWN")
return 2
# Check Server header for Moxa fingerprint
server = headers.get("Server", "")
combined = (body + " " + server).lower()
is_moxa = "moxa" in combined
is_mgate = "mgate" in combined
if not is_moxa:
print(f"[*] Device at {host}:{port} does not appear to be a Moxa product.")
print("UNKNOWN")
return 2
if not is_mgate:
print(f"[*] Moxa device detected but does not appear to be an MGate gateway.")
print("UNKNOWN")
return 2
# Extract model string
model_match = re.search(r"(MGate[\s-]*(?:MB|EIP|W)?[\s-]*[\dA-Za-z]+)", body, re.IGNORECASE)
model = model_match.group(1).strip() if model_match else "MGate (model unknown)"
print(f"[*] Detected: {model}")
# Extract firmware version if visible
fw = re.search(r"(?:firmware|version|fw)[:\s]+[Vv]?([\d.]+)", body, re.IGNORECASE)
if fw:
print(f"[*] Firmware: v{fw.group(1)}")
# Check against affected series
for kw in AFFECTED_KEYWORDS:
if kw in combined:
print(f"[!] AFFECTED: {model} matches vulnerable series keyword '{kw}'")
print(f"[!] CVE-2026-86326: No firmware signature verification.")
print(f"[!] ALL firmware versions affected. No patch available.")
print(f"[!] Ref: Moxa MPSA-269540")
print("VULNERABLE")
return 1
print(f"[*] {model} did not match known affected series keywords.")
print(f"[*] Verify manually against Moxa MPSA-269540 affected product list.")
print("PATCHED")
return 0
if __name__ == "__main__":
if len(sys.argv) < 2:
print(f"Usage: {sys.argv[0]} <host> [port]")
print(f"Example: python3 {sys.argv[0]} 192.168.127.254 80")
sys.exit(2)
host = sys.argv[1]
port = int(sys.argv[2]) if len(sys.argv) > 2 else 80
sys.exit(check(host, port))