CVE-2025-6892: High severity MOXA network security appliances and routers vulnerability
An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate user has logged in, as the system fails to properly validate session context or privilege boundaries. An attacker may leverage this flaw to perform unauthorized privileged operations. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6892?
CVE-2025-6892 is considered to have a high severity due to the potential for unauthorized access to protected API endpoints.
How do I fix CVE-2025-6892?
To fix CVE-2025-6892, ensure that your Moxa network security appliances and routers are updated with the latest firmware patches that address this authorization flaw.
What types of devices are affected by CVE-2025-6892?
CVE-2025-6892 affects Moxa’s network security appliances and routers that utilize the flawed API authentication mechanism.
What can attackers do if they exploit CVE-2025-6892?
If exploited, attackers can gain unauthorized access to sensitive API endpoints, potentially compromising administrative functions and data.
Is my network at risk if I am using Moxa devices with CVE-2025-6892?
Yes, your network may be at risk if using affected Moxa devices, as this vulnerability allows unauthorized access to critical functions.