Back to overview

CVE-2025-6950

CRITICAL
9.9
CVSS 4.0
Description
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby bypassing authentication controls and impersonating any user. Exploitation of this vulnerability can result in complete system compromise, enabling unauthorized access, data theft, and full administrative control over the affected device. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.

Metadata

CVE ID
CVE-2025-6950
State
PUBLISHED
Assigner
Moxa
Reserved
2025-07-01 05:10 UTC
Published
2025-10-17 03:19 UTC
Last updated
2025-10-17 14:26 UTC
Primary CWE
CWE-798
CWE-798: Use of Hard-coded Credentials
Vendor / Product
Moxa / EDR-G9010 Series
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (7)
VendorProductPlatformVersions
Moxa EDF-G1002-BP Series 1.0 ≤ 3.17, 3.21
Moxa EDR-8010 Series 1.0 ≤ 3.17, 3.21
Moxa EDR-G9010 Series 1.0 ≤ 3.14, 3.21
Moxa NAT-102 Series 1.0 ≤ 3.17, 3.21
Moxa NAT-108 Series 1.0 ≤ 3.16, 3.21
Moxa OnCell G4302-LTE4 Series 1.0 ≤ 3.13, 3.21.0
Moxa TN-4900 Series 1.0 ≤ 3.14, 3.21
Weakness (CWE)
CWESourceDescription
CWE-798 cna CWE-798: Use of Hard-coded Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H
Back to overview