PT-2025-14466 · Moxa · Tcpdump
Rex Weng
·
Published
2025-04-02
·
Updated
2025-06-07
·
CVE-2025-0676
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa products (affected versions not specified)
Description
This issue involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tcpdump