An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In certain scenarios, this vulnerability could allow an attacker to gain full administrative control over the affected device, leading to potential account impersonation. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.
History

Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Moxa
Moxa edf-g1002-bp
Moxa edr-8010
Moxa edr-g9010
Moxa nat-102
Moxa nat-108
Moxa oncell G4302-lte4
Moxa tn-4900
Vendors & Products Moxa
Moxa edf-g1002-bp
Moxa edr-8010
Moxa edr-g9010
Moxa nat-102
Moxa nat-108
Moxa oncell G4302-lte4
Moxa tn-4900

Fri, 17 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Oct 2025 03:30:00 +0000

Type Values Removed Values Added
Description An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In certain scenarios, this vulnerability could allow an attacker to gain full administrative control over the affected device, leading to potential account impersonation. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.
Weaknesses CWE-250
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published: 2025-10-17T03:12:02.798Z

Updated: 2025-10-17T14:27:17.368Z

Reserved: 2025-07-01T05:10:25.849Z

Link: CVE-2025-6949

cve-icon Vulnrichment

Updated: 2025-10-17T14:27:14.203Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-17T04:16:12.620

Modified: 2025-10-21T19:31:50.020

Link: CVE-2025-6949

cve-icon Redhat

No data.