CVE-2025-0676: Command Injection Leading to Privilege Escalation in Secure Routers, Cellular Routers, Network Security Appliances

Published: April 2, 2025

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Multiple Moxa secure routers, cellular routers, and network security appliances are affected by a high-severity vulnerability, CVE-2025-0676, which could allow attackers to execute arbitrary systems commands and gain root-level access. 

To mitigate these risks, Moxa has released solutions for the affected products. It is strongly recommended to update to the latest version as soon as possible. 

The identified vulnerability types and potential impacts are listed below:

CVE ID Vulnerability Type Impact

CVE-2025-0676

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity. 

Vulnerability Scoring Details 

ID
Base Score
Vector

Unauthenticated Remote Exploits

CVE-2025-0676

CVSS 4.0: 8.6

AV:N/AC:L/AT:N/PR:H/UI:N/

VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

No

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-251431-cve-2025-0676-command-injection-leading-to-privilege-escalation