PT-2025-43518 · Moxa · Moxa Ethernet Switches

Published

2025-10-23

·

Updated

2025-10-23

·

CVE-2025-1679

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moxa’s Ethernet switches (affected versions not specified)
Description An authenticated administrative attacker can inject malicious scripts into the web service of affected devices, potentially impacting authenticated users interacting with the device’s web interface. This is a stored cross-site scripting (XSS) issue, where injected scripts persist across sessions. The issue does not impact the confidentiality, integrity, and availability of the affected device itself, but may cause some loss of confidentiality and integrity within subsequent systems. The vulnerability involves injecting malicious scripts into the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13531
BDU:2025-13532
CVE-2025-1679

Affected Products

Moxa Ethernet Switches