216.73.216.233

CVE-2025-0415

· Published 02/04/2025 07:15 · Modified 02/04/2025 14:58

Labels: CVE-2025-0415 2025-04-02CVE-2025-0415CWE-78[email protected]

Essential information

Published
02/04/2025 07:15
Modified
02/04/2025 14:58
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
moxa / moxa device cpe:2.3:a:moxa:moxa_device:*:*:*:*:*:*:*:*

References