216.73.216.6

CVE-2025-0676

· Published 02/04/2025 07:15 · Modified 02/04/2025 14:58

Labels: CVE-2025-0676 2025-04-02CVE-2025-0676CWE-78[email protected]

Essential information

Published
02/04/2025 07:15
Modified
02/04/2025 14:58
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
moxa / moxa products cpe:2.3:a:moxa:moxa_products:*:*:*:*:*:*:*:*

References