Stored Cross-site Scripting Vulnerability in Moxa MGate 5121/5122/5123 Series Firmware
CVE-2025-0193
5.2MEDIUM
Key Information:
- Vendor
Moxa
- Vendor
- CVE Published:
- 15 January 2025
What is CVE-2025-0193?
A stored Cross-site Scripting (XSS) flaw is present in the firmware of Moxa's MGate 5121, 5122, and 5123 Series devices due to inadequate validation and encoding of user inputs within the 'Login Message' function. An attacker with administrative privileges can exploit this vulnerability to inject harmful scripts that are persistently stored on the device. These scripts execute when other users visit the login page, which may lead to unauthorized actions or varied impacts depending on those users' privileges.
Affected Version(s)
MGate 5121 Series 1.0
MGate 5122 Series 1.0
MGate 5123 Series 1.0