Stored Cross-site Scripting Vulnerability in Moxa MGate 5121/5122/5123 Series Firmware
CVE-2025-0193
5.2MEDIUM
Key Information:
- Vendor
- Moxa
- Vendor
- CVE Published:
- 15 January 2025
Summary
A stored Cross-site Scripting (XSS) flaw is present in the firmware of Moxa's MGate 5121, 5122, and 5123 Series devices due to inadequate validation and encoding of user inputs within the 'Login Message' function. An attacker with administrative privileges can exploit this vulnerability to inject harmful scripts that are persistently stored on the device. These scripts execute when other users visit the login page, which may lead to unauthorized actions or varied impacts depending on those users' privileges.
Affected Version(s)
MGate 5121 Series 1.0
MGate 5122 Series 1.0
MGate 5123 Series 1.0
References
CVSS V4
Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dmitrii Mosichkin