PT-2025-43519 · Moxa · Moxa Ethernet Switches

Publicado

2025-10-23

·

Atualizado

2025-10-23

·

CVE-2025-1680

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moxa Ethernet switches (affected versions not specified)
Description An acceptance of extraneous untrusted data with trusted data issue exists in Moxa’s Ethernet switches. This allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This is a Host Header Injection issue, where invalid Host headers can be used to redirect users or for phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device or any subsequent systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-13532
CVE-2025-1680

Produtos afetados

Moxa Ethernet Switches