Multiple Moxa secure routers, cellular routers, and network security appliances are affected by a high-severity vulnerability, CVE-2025-0676, which could allow attackers to execute arbitrary systems commands and gain root-level access.
To mitigate these risks, Moxa has released solutions for the affected products. It is strongly recommended to update to the latest version as soon as possible.
The identified vulnerability types and potential impacts are listed below:
| CVE ID | Vulnerability Type | Impact |
|---|---|---|
|
CVE-2025-0676 |
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity. |
Vulnerability Scoring Details
|
ID
|
Base Score
|
Vector
|
Unauthenticated Remote Exploits |
|---|---|---|---|
| CVE-2025-0676 |
CVSS 4.0: 8.6 |
AV:N/AC:L/AT:N/PR:H/UI:N/ VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
No |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-251431-cve-2025-0676-command-injection-leading-to-privilege-escalation