CVE-2026-3867CWE-282

An improper ownership management vulnerability has been identified in Moxa’s Secure Router

Medium · published April 27, 2026

CVSS v4.0
6.0
EPSS
0%
Percentile
15.0
In the wild
Unconfirmed
What it is

An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the hashed password of the administrative account. Successful exploitation of this vulnerability could allow an attacker to obtain sensitive information. Exploitation is only possible under a specific condition — when the configuration file has been exported. This vulnerability does not impact the integrity or availability of the affected product, and no confidentiality, integrity, or availability impact to the subsequent system has been identified.

The record
Technical detail
CVSS v4.0
6.0 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00240 · 15.0th percentile
Weakness
CWE-282 · Improper Ownership Management
Published
2026-04-27T02:54Z
EPSS history
Timeline
  • 27 APR 02:54Z
    An improper ownership management vulnerability has been identified in Moxa’s Secure Router
    cvelistv5