CVE-2025-6950
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby bypassing authentication controls and impersonating any user. Exploitation of this vulnerability can result in complete system compromise, enabling unauthorized access, data theft, and full administrative control over the affected device. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.65%
- CWE
- CWE-798
- Published
- 2025-10-17
- Last modified
- 2026-03-12
Affected products
- Moxa EDR-G9010 Series
- Moxa EDR-G9010 Series
- Moxa EDR-8010 Series
- Moxa EDR-8010 Series
- Moxa EDF-G1002-BP Series
- Moxa EDF-G1002-BP Series
- Moxa TN-4900 Series
- Moxa TN-4900 Series
Weakness type
Related vulnerabilities
- CVE-2026-75940 — A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the...
- CVE-2026-17038 — Use of Hard-coded Credentials in drEryk Gabinet
- CVE-2026-81640 — Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Credentials
- CVE-2026-79731 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79950 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79740 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79738 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...