PT-2025-43519 · Moxa · Moxa Ethernet Switches

Published

2025-10-23

·

Updated

2025-10-23

·

CVE-2025-1680

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moxa Ethernet switches (affected versions not specified)
Description An acceptance of extraneous untrusted data with trusted data issue exists in Moxa’s Ethernet switches. This allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This is a Host Header Injection issue, where invalid Host headers can be used to redirect users or for phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device or any subsequent systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13532
CVE-2025-1680

Affected Products

Moxa Ethernet Switches