CVE-2025-0676 Details
Description
This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity.
A command injection vulnerability has been identified in tcpdump within multiple Moxa product series, including secure routers, cellular routers, and network security appliances. This vulnerability allows an authenticated attacker with console access to exploit improper input validation, injecting and executing system commands. Successful exploitation could lead to privilege escalation, granting root access and allowing persistent control over the device. This could disrupt network services and impact the availability of downstream systems reliant on the device's connectivity.
Users are advised to upgrade to the latest firmware version. Specific upgrade instructions can be found in the Moxa Security Advisory MPSA-259491.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 2, 2025CISA-ADP
Assessed Apr 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.moxa.com/en/support/product-support/security-advisory/mpsa-259491-cve-2025-0676-command-injection-leading-to-privilege-escalation | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Moxa EDF-G1002-BP | All versions |
CPE
Remediation
| |
| Moxa EDR-810 | <= 5.12.39 (semver) |
CPE
Remediation
| |
| Moxa EDR-8010 | All versions |
CPE
Remediation
| |
| Moxa EDR-G9004 | <= 3.14 |
CPE
Remediation
| |
| Moxa EDR-G9010 | <= 3.14 |
CPE
Remediation
| |
| Moxa NAT-102 | All versions |
CPE
Remediation
| |
| Moxa OnCell G4302-LTE4 | All versions |
CPE
Remediation
| |
| Moxa TN-4900 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2025 | New CVE Received | [email protected] |
Volerion