216.73.217.22

CVE-2025-6892

· Published 17/10/2025 02:15 · Modified 17/10/2025 02:15

Labels: CVE-2025-6892 2025-10-17CVE-2025-6892CWE-863[email protected]

Essential information

Published
17/10/2025 02:15
Modified
17/10/2025 02:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate user has logged in, as the system fails to properly validate session context or privilege boundaries. An attacker may leverage this flaw to perform unauthorized privileged operations. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
moxa / network security appliances cpe:2.3:a:moxa:network_security_appliances:*:*:*:*:*:*:*:*
moxa / routers cpe:2.3:a:moxa:routers:*:*:*:*:*:*:*:*

References