CVE-2025-6950 Details
Description
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby bypassing authentication controls and impersonating any user. Exploitation of this vulnerability can result in complete system compromise, enabling unauthorized access, data theft, and full administrative control over the affected device. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.
A vulnerability has been identified in Moxa's network security appliances and routers, where a hard-coded secret key is used to sign JSON Web Tokens (JWT) for authentication. This flaw allows an unauthenticated attacker to forge valid tokens, bypass authentication controls, and impersonate any user. Exploitation can lead to complete system compromise, unauthorized access, data theft, and full administrative control over the affected device. While this vulnerability severely impacts the device's own security, it does not affect the confidentiality or integrity of any subsequent systems.
Users are advised to update to version 3.21 or later. For the OnCell G4302-LTE4 Series, please contact Moxa Technical Support for the security patch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 17, 2025CISA-ADP
Assessed Oct 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Moxa EDR-G9010 | <v3.21 |
CPE
Remediation
| |
| Moxa EDR-8010 | <v3.21 |
CPE
Remediation
| |
| Moxa EDF-G1002-BP | <v3.21 |
CPE
Remediation
| |
| Moxa TN-4900 | <v3.21 |
CPE
Remediation
| |
| Moxa NAT-102 | <v3.21 |
CPE
Remediation
| |
| Moxa NAT-108 | <v3.21 |
CPE
Remediation
| |
| Moxa OnCell G4302-LTE4 | <v3.21 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 17, 2025 | New CVE Received | [email protected] |
Volerion