Stored Cross-Site Scripting Vulnerability in Moxa Ethernet Switches
CVE-2025-1679

4.8MEDIUM

Key Information:

Vendor

Moxa

Vendor
CVE Published:
23 October 2025

What is CVE-2025-1679?

A stored cross-site scripting vulnerability has been found in Moxa's Ethernet switches, allowing an authenticated administrative attacker to inject malicious scripts into the device's web service. These scripts persist across sessions, which may affect authenticated users who interact with the device's web interface. While this vulnerability does not compromise the overall availability of the device, it may lead to a decrease in confidentiality and integrity of the information processed by subsequent systems.

Affected Version(s)

TN-4500A Series 1.0 <= 3.13

TN-5500A Series 1.0 <= 3.13

TN-G4500 Series 1.0 <= 5.5

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aarón Flecha Menéndez
VĂ­ctor Bello Cuevas
.
CVE-2025-1679 : Stored Cross-Site Scripting Vulnerability in Moxa Ethernet Switches