Stored Cross-Site Scripting Vulnerability in Moxa Ethernet Switches
CVE-2025-1679
4.8MEDIUM
Key Information:
- Vendor
Moxa
- Vendor
- CVE Published:
- 23 October 2025
What is CVE-2025-1679?
A stored cross-site scripting vulnerability has been found in Moxa's Ethernet switches, allowing an authenticated administrative attacker to inject malicious scripts into the device's web service. These scripts persist across sessions, which may affect authenticated users who interact with the device's web interface. While this vulnerability does not compromise the overall availability of the device, it may lead to a decrease in confidentiality and integrity of the information processed by subsequent systems.
Affected Version(s)
TN-4500A Series 1.0 <= 3.13
TN-5500A Series 1.0 <= 3.13
TN-G4500 Series 1.0 <= 5.5
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aarón Flecha Menéndez
VĂctor Bello Cuevas