7.0
HIGH CVSS 4.0
CVE-2026-4483
Moxa MxGeneralIo Insufficient Access Control IOCTL Vulnerability
Description

An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system memory. A local attacker with high privileges could abuse these interfaces to perform unauthorized operations. Successful exploitation may result in privilege escalation on Windows 7 systems or cause a system crash (BSoD) on Windows 10 and 11 systems, leading to a denial-of-service condition. The vulnerability could slightly affect the confidentiality and integrity of the device, but availability might be heavily impacted. No impact to the subsequent system has been identified.

INFO

Published Date :

April 8, 2026, 8:16 a.m.

Last Modified :

July 24, 2026, 8:10 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2026-4483 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Moxa mxgeneralio
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 4.0 HIGH 2e0a0ee2-d866-482a-9f5e-ac03d156dbaa
CVSS 4.0 HIGH [email protected]
Solution
Apply vendor patches to MxGeneralIo to fix access control and prevent privilege escalation or system crashes.
  • Update the MxGeneralIo utility to the latest version.
  • Restrict access to IOCTL methods.
  • Review and harden system configurations.
  • Monitor for unauthorized system access.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-4483.

URL Resource
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-254811-cve-2026-4483-exposed-ioctl-with-insufficient-access-control-vulnerability-in-the-utility-for-x86-computers
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-4483 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-4483 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-4483 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-4483 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Translated by [email protected]

    Jul. 24, 2026

    Action Type Old Value New Value
    Added Translation Title: MxGeneralIo de Moxa, Description: Un IOCTL expuesto con una vulnerabilidad de control de acceso insuficiente ha sido identificado en la utilidad, MxGeneralIo, para los ordenadores industriales x86 de Moxa. La utilidad afectada, MxGeneralIo, expone métodos IOCTL que permiten acceso directo de lectura y escritura a MSR y a la memoria del sistema. Un atacante local con privilegios elevados podría abusar de estas interfaces para realizar operaciones no autorizadas. La explotación exitosa puede resultar en escalada de privilegios en sistemas Windows 7 o causar un fallo del sistema (BSoD) en sistemas Windows 10 y 11, lo que lleva a una condición de denegación de servicio. La vulnerabilidad podría afectar ligeramente la confidencialidad e integridad del dispositivo, pero la disponibilidad podría verse gravemente impactada. Ningún impacto en el sistema subsiguiente ha sido identificado.
  • CVE Modified by [email protected]

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'Moxa', 'product': 'MxGeneralIo', 'versions': [{'status': 'affected', 'version': '1.0', 'lessThan': '1.4.0', 'versionType': 'custom'}], 'platforms': ['Windows 7 x86'], 'defaultStatus': 'unaffected'}, {'vendor': 'Moxa', 'product': 'MxGeneralIo', 'versions': [{'status': 'affected', 'version': '1.0', 'lessThan': '1.5.0', 'versionType': 'custom'}], 'platforms': ['Windows 10', 'Windows 11'], 'defaultStatus': 'unaffected'}, {'vendor': 'Moxa', 'product': 'MxGeneralIo', 'versions': [{'status': 'affected', 'version': '1.0', 'lessThan': '1.4.0', 'versionType': 'custom'}], 'platforms': ['Windows 7 x64'], 'defaultStatus': 'unaffected'}]
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 17, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-4483', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-04-08T13:53:18.890748Z'}
  • New CVE Received by [email protected]

    Apr. 08, 2026

    Action Type Old Value New Value
    Added Description An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system memory. A local attacker with high privileges could abuse these interfaces to perform unauthorized operations. Successful exploitation may result in privilege escalation on Windows 7 systems or cause a system crash (BSoD) on Windows 10 and 11 systems, leading to a denial-of-service condition. The vulnerability could slightly affect the confidentiality and integrity of the device, but availability might be heavily impacted. No impact to the subsequent system has been identified.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-782
    Added Reference https://www.moxa.com/en/support/product-support/security-advisory/mpsa-254811-cve-2026-4483-exposed-ioctl-with-insufficient-access-control-vulnerability-in-the-utility-for-x86-computers
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.