PT-2025-42579 · Moxa · Moxa Routers+1

Published

2025-10-16

·

Updated

2025-10-21

·

CVE-2025-6949

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Moxa network security appliances and routers (affected versions not specified)
Description An authorization flaw exists in the API of Moxa network security appliances and routers. An authenticated, low-privileged user can create a new administrator account, even with a username that matches an existing user. This could allow an attacker to gain full administrative control over the device. Successful exploitation impacts the confidentiality, integrity, and availability of the affected device. The /api endpoint is involved in this issue, allowing unauthorized account creation through a flaw in the createAccount() function. The vulnerable parameter is username.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13185
CVE-2025-6949

Affected Products

Moxa Network Security Appliances
Moxa Routers