Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classified as stored cross-site scripting (XSS); attackers inject malicious scripts into the system, and the scripts persist across sessions. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of availability within any subsequent systems but has some loss of confidentiality and integrity within the subsequent system.
History

Fri, 24 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Moxa
Moxa tn-4500a
Moxa tn-5500a
Moxa tn-g4500
Moxa tn-g6500
Vendors & Products Moxa
Moxa tn-4500a
Moxa tn-5500a
Moxa tn-g4500
Moxa tn-g6500

Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 14:00:00 +0000

Type Values Removed Values Added
Description Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classified as stored cross-site scripting (XSS); attackers inject malicious scripts into the system, and the scripts persist across sessions. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of availability within any subsequent systems but has some loss of confidentiality and integrity within the subsequent system.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published: 2025-10-23T13:51:27.285Z

Updated: 2025-10-23T14:37:22.233Z

Reserved: 2025-02-25T08:08:17.451Z

Link: CVE-2025-1679

cve-icon Vulnrichment

Updated: 2025-10-23T14:37:13.604Z

cve-icon NVD

Status : Received

Published: 2025-10-23T14:15:35.653

Modified: 2025-10-23T14:15:35.653

Link: CVE-2025-1679

cve-icon Redhat

No data.