Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Moxa Switches Vulnerability Enables Unauthorized Access through Authentication Bypass

Moxa has released a critical security advisory concerning a significant vulnerability in multiple series of its industrial Ethernet switches. This vulnerability, identified as CVE-2024-12297, permits remote attackers to bypass authentication mechanisms,…

Moxa has released a critical security advisory concerning a significant vulnerability in multiple series of its industrial Ethernet switches. This vulnerability, identified as CVE-2024-12297, permits remote attackers to bypass authentication mechanisms, potentially allowing unauthorized access to critical network infrastructure. With a CVSS v4.0 score of 9.2, it is classified as critical, necessitating immediate attention from administrators overseeing operational technology (OT) environments.

The vulnerability is rooted in a flaw within the frontend authorization logic of the affected devices. Identified as CWE-656 (Reliance on Security Through Obscurity), the flaw affects the manner in which the switches verify user credentials. Despite utilizing both client-side and back-end server verification, the implementation contains weaknesses exploitable by attackers.

Exploitation of these flaws allows an unauthenticated attacker to perform password brute-forcing (CAPEC-49) or utilize MD5 collision attacks to forge authentication hashes. Successful exploitation results in bypassing the login screen, leading to full device compromise. Given the role of these switches in industrial networks, such access could allow threat actors to disrupt operations, intercept traffic, or move laterally to other critical assets within the OT network.

CVE ID CVSS v4.0 Score Vector Impact

CVE-2024-12297 9.2 (Critical) AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L Authentication Bypass, Unauthorized Access

Moxa has released a critical security advisory concerning a significant vulnerability in multiple series of its industrial Ethernet switches.
Sam Quinlan · Thehackingpost

The vulnerability affects the TN-A and TN-G series of managed Ethernet switches. Moxa has released specific patch versions to address the flaw. These patches must be obtained by contacting Moxa Technical Support directly.

Product Series Affected Versions Remediation (Patch Version)

TN-A Series (TN-4500A, TN-5500A) Firmware v4.1 and earlier Contact Support for v3.13.255

TN-G Series (TN-G4500, TN-G6500) Firmware v5.5 and earlier Contact Support for v5.5.255

Advertisement

Mitigation and Security Best Practices

For organizations unable to immediately apply the firmware updates, Moxa recommends a defense-in-depth approach to mitigate the risk of exploitation:

Network Segmentation: Utilize VLANs and physical separation to isolate operational networks from enterprise traffic. Access Control: Implement Access Control Lists (ACLs) and firewalls to restrict device management interfaces to trusted IP addresses only. Disable Internet Exposure: Ensure these switches are not directly exposed to the public internet. VPN Usage: Mandate encrypted communication protocols (SSH, VPN) for all remote management tasks. Log Monitoring: Enable event logging and regularly audit trails for anomalies, specifically focusing on repeated failed login attempts or unauthorized access indicators.

Administrators are advised to apply the relevant patches immediately to prevent potential brute-force or hash collision attacks against their industrial infrastructure.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories