CVE-2025-6894: Medium severity MOXA network security appliances and routers vulnerability

Published Oct 17, 2025
·
Updated

An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative ping function, which is restricted to higher-privileged roles. This vulnerability enables the user to perform internal network reconnaissance, potentially discovering internal hosts or services that would otherwise be inaccessible. Repeated exploitation could lead to minor resource consumption. While the overall impact is limited, it may result in some loss of confidentiality and availability on the affected device. There is no impact on the integrity of the device, and the vulnerability does not affect any subsequent systems.

Affected Software

1 affected component
MOXA network security appliances and routers

Remediation

Information

Moxa has developed appropriate solutions to address the vulnerability. Please refer to  https://www.moxa.com/en/support/product-support/security-advisory/mpsa-258121-cve-2025-6892,-cve-202... https://www.moxa.com/en/support/product-support/security-advisory/mpsa-258121-cve-2025-6892,-cve-2025-6893,-cve-2025-6894,-cve-2025-6949,-cve-2025-6950-multiple-vulnerabilities-in-netwo

Event History

Oct 17, 2025
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-6894?

CVE-2025-6894 is classified as an Execution with Unnecessary Privileges vulnerability.

2

How does CVE-2025-6894 affect Moxa's network security appliances and routers?

CVE-2025-6894 allows authenticated low-privileged users to perform administrative functions, such as executing the `ping` command.

3

Who is at risk from CVE-2025-6894?

Any authenticated user with low privileges on affected Moxa network security appliances and routers is at risk from CVE-2025-6894.

4

What steps can be taken to mitigate CVE-2025-6894?

To mitigate CVE-2025-6894, update to the latest firmware or security patches recommended by Moxa.

5

Is CVE-2025-6894 widely exploited in the wild?

As of the current information available, there is no indication that CVE-2025-6894 is widely exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203