Stored Cross-Site Scripting Vulnerability in Moxa Ethernet Switches
CVE-2025-1679
Key Information:
- Vendor
Moxa
- Vendor
- CVE Published:
- 23 October 2025
What is CVE-2025-1679?
A stored cross-site scripting vulnerability has been found in Moxa's Ethernet switches, allowing an authenticated administrative attacker to inject malicious scripts into the device's web service. These scripts persist across sessions, which may affect authenticated users who interact with the device's web interface. While this vulnerability does not compromise the overall availability of the device, it may lead to a decrease in confidentiality and integrity of the information processed by subsequent systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TN-4500A Series 1.0 <= 3.13
TN-5500A Series 1.0 <= 3.13
TN-G4500 Series 1.0 <= 5.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved