Authorization Flaw in Moxa Network Security Appliances and Routers
CVE-2025-6949
9.3CRITICAL
Key Information:
- Vendor
Moxa
- Vendor
- CVE Published:
- 17 October 2025
What is CVE-2025-6949?
A significant authorization flaw has been discovered in Moxa's network security appliances and routers, allowing low-privileged users to create new administrator accounts with identical usernames to existing users. This vulnerability can potentially enable attackers to assume full administrative privileges over affected devices, raising concerns regarding account impersonation and overall system security. While the immediate risk is confined to the affected device, it poses severe threats to operational integrity and availability.
Affected Version(s)
EDF-G1002-BP Series 1.0 <= 3.17
EDR-8010 Series 1.0 <= 3.17
EDR-G9010 Series 1.0 <= 3.14