PT-2025-43518 · Moxa · Moxa Ethernet Switches
Published
2025-10-23
·
Updated
2025-10-23
·
CVE-2025-1679
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moxa’s Ethernet switches (affected versions not specified)
Description
An authenticated administrative attacker can inject malicious scripts into the web service of affected devices, potentially impacting authenticated users interacting with the device’s web interface. This is a stored cross-site scripting (XSS) issue, where injected scripts persist across sessions. The issue does not impact the confidentiality, integrity, and availability of the affected device itself, but may cause some loss of confidentiality and integrity within subsequent systems. The vulnerability involves injecting malicious scripts into the system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Ethernet Switches