Stored Cross-site Scripting Vulnerability in Moxa MGate 5121/5122/5123 Series Firmware
CVE-2025-0193
Key Information:
- Vendor
Moxa
- Vendor
- CVE Published:
- 15 January 2025
What is CVE-2025-0193?
A stored Cross-site Scripting (XSS) flaw is present in the firmware of Moxa's MGate 5121, 5122, and 5123 Series devices due to inadequate validation and encoding of user inputs within the 'Login Message' function. An attacker with administrative privileges can exploit this vulnerability to inject harmful scripts that are persistently stored on the device. These scripts execute when other users visit the login page, which may lead to unauthorized actions or varied impacts depending on those users' privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MGate 5121 Series 1.0
MGate 5122 Series 1.0
MGate 5123 Series 1.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved