Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Moxa

Moxa Vendor Cyber Rating & Cyber Score

moxa.com

Critical connectivity in automation is not just about having a fast connection; it is about making people's lives better and more secure. Moxa's connectivity technology helps to make your ideas real. We develop reliable network solutions that enable devices to connect, communicate, and collaborate with systems, processes, and people.


Moxa A.I CyberSecurity Scoring

Moxa
Company Information
Website:https://www.moxa.com/
Employees number:1,407
Number of followers:61,948
NAICS:33325
Industry Type:Automation Machinery Manufacturing
Homepage:moxa.com
Moxa Risk Score (AI oriented)
Between 750 and 799
logo
MoxaAutomation Machinery Manufacturing
Updated:
30/03/2026
752/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Moxa Global Score (TPRM)
xxxx
logo
MoxaAutomation Machinery Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Moxa
MoxaFair
Current Score
752Baa (FAIR)
01000
3 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
754Before Incident
AUGUST 2026
753Before Incident
JULY 2026
753Before Incident
JUNE 2026
753Before Incident
MAY 2026
752Before Incident
APRIL 2026
752Before Incident
MARCH 2026
751Before Incident
FEBRUARY 2026
756Before Incident
Vulnerability
04 Feb 2026Moxa
Moxa: Moxa Switches Vulnerability Allows Attackers to Bypass Authentication

Critical Authentication Bypass Flaw in Moxa Industrial Switches Exposes Networks to Remote Attacks

751After Incident
CRITICAL-5
MOX1770302285
Critical Authentication Bypass Flaw in Moxa Industrial Switches Exposes Networks to Remote Attacks Moxa has released a critical security advisory (MPSA-241409) addressing a severe authentication bypass vulnerability in its industrial Ethernet switches, tracked as CVE-2024-12297 (CVSS 9.2). The flaw, disclosed on February 4, 2026, affects the TN-A and TN-G series and stems from improper coordination between client-side and backend authorization logic. The vulnerability, dubbed "Frontend Authorization Logic Disclosure," allows attackers to exploit weak authentication mechanisms via brute-force attacks or MD5 hash collision techniques to forge credentials. Successful exploitation could grant unauthorized access to switch management interfaces, enabling lateral movement or configuration tampering within industrial networks. The root cause was identified as reliance on obscured authentication logic rather than secure server-side validation. Affected Products & Remediation: - TN-A Series (TN-4500A, TN-5500A): Firmware v4.1 and earlier – Patch to v3.13.255. - TN-G Series (TN-G4500, TN-G6500): Firmware v5.5 and earlier – Patch to v5.5.255. For organizations unable to immediately apply patches, Moxa recommends restricting network access to trusted hosts, enabling network segmentation, and auditing logs for suspicious activity. The vulnerability poses a high risk to industrial communication networks, emphasizing the need for prompt patching and post-update verification.
INCIDENT DETAILS -
TYPE
Authentication Bypass
IMPACT
Systems Affected: Industrial Ethernet switches (TN-A and TN-G series)Operational Impact: Unauthorized access to switch management interfaces, lateral movement, configuration tampering
JANUARY 2026
756Before Incident
DECEMBER 2025
760Before Incident
Vulnerability
29 Dec 2025Moxa
Moxa, Siemens, Hitachi Energy and Mitsubishi Electric: Team Cymru warns exposed ICS and OT devices targeted by nation-state actors raise industrial, critical infrastructure risks

Exposed ICS/OT Devices Under Nation-State Threat: Key Findings from Team Cymru’s Research

755After Incident
CRITICAL-5
SIEMOXMITHIT1774866497
Exposed ICS/OT Devices Under Nation-State Threat: Key Findings from Team Cymru’s Research Team Cymru’s latest research reveals alarming vulnerabilities in industrial control systems (ICS) and operational technology (OT) environments, highlighting how exposed devices remain prime targets for hostile nation-state actors. The report examines three case studies demonstrating the persistent risks to critical infrastructure, driven by poor security practices and active exploitation campaigns. ### Case Study 1: Destructive Attack on Polish Power Grid In December 2025, the Russian-linked Dragonfly group targeted Poland’s power grid by exploiting Hitachi RTU560 remote terminal units critical for electrical grid stability. Attackers leveraged default credentials on internet-exposed web interfaces, a common but preventable weakness. Once inside, they deployed a "hard brick" attack, uploading corrupted firmware that forced devices into an infinite reboot loop, rendering them inoperable. While the immediate impact was limited to communication disruptions, the attack demonstrated how basic access vectors could escalate into broader infrastructure degradation. ### Case Study 2: Moxa NPort Devices Compromised via Default Credentials The same Dragonfly campaign also targeted Moxa NPort devices, which bridge legacy serial equipment with modern IP networks. Despite supporting secure protocols like TLS and SSH, many devices remained vulnerable due to unrotated factory-default logins. Attackers gained administrative access, reset devices to factory settings, and reconfigured IP addresses to 127.0.0.1, effectively cutting them off from the network. Recovery required manual intervention, causing prolonged operational downtime. ### Case Study 3: Rockwell Automation Vulnerabilities Enable Remote Exploitation In July 2023, Rockwell Automation and CISA disclosed critical vulnerabilities (CVE-2023-3595, CVE-2023-3596) in Allen-Bradley ControlLogix communication modules. These flaws, attributed to a nation-state actor, allowed remote code execution via maliciously crafted Common Industrial Protocol (CIP) messages. Security firm Dragos compared the threat to TRISIS/TRITON-level attacks, noting that compromised modules could manipulate process data, maintain persistence, and evade detection potentially leading to catastrophic failures without operator awareness. ### Exposure Landscape: Key Statistics Team Cymru’s data reveals a troubling concentration of exposed devices: - Rockwell Automation dominates with 68.1% (6,653 unique IPs) of detected targets, reflecting its widespread use in North American and global industrial automation. - Moxa accounts for 15.7% (1,532 IPs), with attackers leveraging its networking equipment to pivot deeper into OT networks. - Other major vendors include Siemens (7.3%), Schneider Electric (4.5%), Hitachi Energy (4.2%), and Mitsubishi Electric (0.1%), all critical to European and Asian infrastructure. Geographically, the U.S. leads with 45.4% of exposed devices (1,269 IPs), a concern given Dragonfly and Volt Typhoon’s history of pre-positioning in critical sectors. Russia (4.3%), Ukraine (3.0%), and Taiwan (2.6%) also rank high, reflecting ongoing cyber warfare and geopolitical tensions. ### Broader Implications The research underscores a critical gap in ICS/OT security: thousands of devices remain internet-exposed despite best practices advising against direct public access. The persistence of default credentials, unpatched vulnerabilities, and nation-state reconnaissance efforts signals an urgent need for improved IT/OT convergence and proactive threat mitigation. Without intervention, these exposures risk enabling disruptive or destructive attacks on essential services.
INCIDENT DETAILS -
TYPE
Cyber EspionageSabotageRemote Code Execution
MOTIVATION
Disruption of Critical InfrastructureCyber WarfareGeopolitical Tensions
IMPACT
Hitachi RTU560Moxa NPortAllen-Bradley ControlLogixDowntime: Prolonged operational downtime due to manual recoveryCommunication disruptionsInfinite reboot loopsNetwork isolationProcess data manipulation
NOVEMBER 2025
760Before Incident
OCTOBER 2025
760Before Incident
JUNE 2024
753Before Incident
Vulnerability
16 Jun 2024Moxa
Moxa

Critical Flaw in Moxa’s Industrial Ethernet Switches

758After Incident
CRITICAL-5
MOX225031025
A critical flaw in Moxa’s industrial Ethernet switches, CVE-2024-12297, risks compromising device integrity allowing unauthorized access to sensitive industrial systems. Successful exploitation could result in full administrative access, network segmentation breaches, traffic interception, and disruption of critical infrastructure operations such as power grids and manufacturing plants. The vulnerability exhibits high exploitable potential due to its network attack vector and low attack complexity. Moxa has issued firmware patches to mitigate the flaw, and authorities like the UAE Cyber Security Council have emphasized the importance of patching against the backdrop of potential severe impacts in critical sectors like oil, gas, and transportation.
INCIDENT DETAILS -
TYPE
Vulnerability Exploit
MOTIVATION
Unauthorized Access
IMPACT
Industrial Ethernet SwitchesOperational Impact: Disruption of critical infrastructure operations

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Moxa ?
?
What was Moxa's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Moxa's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Moxa's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Moxa's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Moxa's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Moxa ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Moxa's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?