Description

An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This vulnerability is classified as Host Header Injection, where invalid Host headers can manipulate to redirect users, forge links, or phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of confidentiality, integrity, and availability within any subsequent systems.

INFO

Published Date :

2025-10-23T13:56:39.744Z

Last Modified :

2025-10-23T14:35:30.379Z

Source :

Moxa
AFFECTED PRODUCTS

The following products are affected by CVE-2025-1680 vulnerability.

Vendors Products
Moxa
  • Tn-4500a
  • Tn-5500a
  • Tn-g4500
  • Tn-g6500

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability