CVE Database
/

CVE-2025-0193

Back to search

CVE-2025-0193

Published: Jan 15, 2025

Modified: Jan 15, 2025

PUBLISHED

Description

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.

VendorProductVersions

Moxa

MGate 5121 Series

affected
1.0

Moxa

MGate 5122 Series

affected
1.0

Moxa

MGate 5123 Series

affected
1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now