Database/Control plane, storage & DevOps

Moxa NPort W2150A / W2250A wireless device server: A remote attacker can crash or potentially gain code execution
Impact
A remote attacker can crash or potentially gain code execution on the device server by sending a crafted payload to its web management service — the built-in web server has a stack-based buffer overflow.
Who can reach it
Remote, over the network — no authentication mentioned as a prerequisite in the vendor advisory; reachability to the web service is sufficient to trigger the overflow.
What to do
Firmware upgrade to the version in Moxa's MPSA-238975 advisory. Flash and reboot each unit; serial sessions on that device drop briefly during the update.
References
Related entries
- Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCVE-2017-16727 · Moxa NPort W2150A / W2250A wireless device serverCritical
- AmdPlatformRasSspSmm - SMM callout (AMD-SB-7028): An SMM callout in the platform RAS SMM driver lets ring-0 code modifyCVE-2024-21924 · AmdPlatformRasSspSmm - SMM callout (AMD-SB-7028)High
- AmdPspP2CmboxV2 - SMM input validation (AMD-SB-7027): Insufficient input validation in the AmdPspP2CmboxV2 SMM driverCVE-2024-21925 · AmdPspP2CmboxV2 - SMM input validation (AMD-SB-7027)High
- OpenTelemetry Collector: Unsafe decompressionCVE-2024-36129 · OpenTelemetry CollectorHigh
- VMware Aria Automation (DOM-based XSS, token theft): A crafted URL steals the access token of a logged-in AriaCVE-2025-22249 · VMware Aria Automation (DOM-based XSS, token theft)High
- OpenShift Hive / MCE / ACM (vCenter credential exposure): vCenter credentials are written into the ClusterProvisionCVE-2025-2241 · OpenShift Hive / MCE / ACM (vCenter credential exposure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.