Description

Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classified as stored cross-site scripting (XSS); attackers inject malicious scripts into the system, and the scripts persist across sessions. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of availability within any subsequent systems but has some loss of confidentiality and integrity within the subsequent system.

INFO

Published Date :

2025-10-23T13:51:27.285Z

Last Modified :

2025-10-23T14:37:22.233Z

Source :

Moxa
AFFECTED PRODUCTS

The following products are affected by CVE-2025-1679 vulnerability.

Vendors Products
Moxa
  • Tn-4500a
  • Tn-5500a
  • Tn-g4500
  • Tn-g6500

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability