CVE-2025-6950 is a critical Use of Hard-coded Credentials vulnerability affecting Moxa’s network security appliances and routers. An unauthenticated attacker can exploit a hard-coded secret key used for JWT signing to forge valid authentication tokens, bypassing security controls. This allows for complete system compromise, including unauthorized access, data theft, and full administrative control over the device. While the vulnerability has a CVSS score of 9.9 (CRITICAL) due to its network attack vector and low complexity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Moxa | EDF-G1002-BP Series | >= 1.0, <= 3.17CNA affecteddefault unaffected | |
| Moxa | EDR-8010 Series | >= 1.0, <= 3.17CNA affecteddefault unaffected | |
| Moxa | EDR-G9010 Series | >= 1.0, <= 3.14CNA affecteddefault unaffected | |
| Moxa | NAT-102 Series | >= 1.0, <= 3.17CNA affecteddefault unaffected | |
| Moxa | NAT-108 Series | >= 1.0, <= 3.16CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.