Authorization Flaw in Moxa Network Security Appliances and Routers
CVE-2025-6949

9.3CRITICAL

Key Information:

Vendor

Moxa

Vendor
CVE Published:
17 October 2025

What is CVE-2025-6949?

A significant authorization flaw has been discovered in Moxa's network security appliances and routers, allowing low-privileged users to create new administrator accounts with identical usernames to existing users. This vulnerability can potentially enable attackers to assume full administrative privileges over affected devices, raising concerns regarding account impersonation and overall system security. While the immediate risk is confined to the affected device, it poses severe threats to operational integrity and availability.

Affected Version(s)

EDF-G1002-BP Series 1.0 <= 3.17

EDR-8010 Series 1.0 <= 3.17

EDR-G9010 Series 1.0 <= 3.14

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6949 : Authorization Flaw in Moxa Network Security Appliances and Routers