CVE-2025-0193 describes a stored Cross-site Scripting (XSS) vulnerability in Moxa MGate 5121/5122/5123 Series firmware v1.0, stemming from insufficient input sanitization in the "Login Message" function. An authenticated administrator can inject malicious scripts that execute when other users access the login page, potentially leading to unauthorized actions depending on the victim's privileges. With a CVSS score of 5.2 (Medium), this vulnerability requires high privileges and user interaction for exploitation, but can result in high impact to scope, integrity, and availability. Currently, there is no public exploit code available, nor is there any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Moxa | MGate 5121 Series | 1.0CNA affecteddefault unaffected | |
| Moxa | MGate 5122 Series | 1.0CNA affecteddefault unaffected | |
| Moxa | MGate 5123 Series | 1.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.