Stored Cross-site Scripting Vulnerability in Moxa MGate 5121/5122/5123 Series Firmware
CVE-2025-0193

5.2MEDIUM

Key Information:

Vendor
Moxa
Vendor
CVE Published:
15 January 2025

Summary

A stored Cross-site Scripting (XSS) flaw is present in the firmware of Moxa's MGate 5121, 5122, and 5123 Series devices due to inadequate validation and encoding of user inputs within the 'Login Message' function. An attacker with administrative privileges can exploit this vulnerability to inject harmful scripts that are persistently stored on the device. These scripts execute when other users visit the login page, which may lead to unauthorized actions or varied impacts depending on those users' privileges.

Affected Version(s)

MGate 5121 Series 1.0

MGate 5122 Series 1.0

MGate 5123 Series 1.0

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Mosichkin
.