CVE-2022-41313 is a stored cross-site scripting (XSS) vulnerability affecting Moxa SDS-3008 Series Industrial Ethernet Switches (firmware 2.1). An authenticated attacker can inject malicious JavaScript into the "switch_contact" form field via a specially crafted HTTP request. This vulnerability has a CVSS score of 5.4 (Medium), indicating a low attack complexity and requiring user interaction, with potential impacts of limited confidentiality and integrity. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, suggesting it is not actively exploited. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1CPE matchmatch criteria | cpe:2.3:o:moxa:sds-3008_firmware:*:*:*:*:*:*:*:* | ||
<= 2.1CPE matchmatch criteria | cpe:2.3:o:moxa:sds-3008-t_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.