Vulnerabilities
Vulnerable Software
Mobatek:  >> Mobaxterm  >> 22.2  Security Vulnerabilities
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a malicious executable earlier in the search order, resulting in arbitrary code execution in the context of the affected user.
CVSS Score
8.5
EPSS Score
0.0
Published
2026-03-09
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.
CVSS Score
9.1
EPSS Score
0.005
Published
2022-12-06


Contact Us

Shodan ® - All rights reserved