A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.

Project Subscriptions

Vendors Products
Uc-1200a Series Subscribe
Advisories

No advisories yet.

Fixes

Solution

Please refer to Moxa's security advisory.


Workaround

No workaround given by the vendor.

History

Fri, 12 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Description A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.
First Time appeared Moxa
Moxa uc-1200a Series
Weaknesses CWE-325
CPEs cpe:2.3:a:moxa:uc-1200a_series:*:*:os_image_mil3_secure_version_:*:*:*:*:*
Vendors & Products Moxa
Moxa uc-1200a Series
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published:

Updated: 2026-06-12T10:00:33.056Z

Reserved: 2026-05-22T02:41:04.026Z

Link: CVE-2026-9266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-12T11:16:23.297

Modified: 2026-06-12T11:16:23.297

Link: CVE-2026-9266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T12:30:05Z

Weaknesses