{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-1680",
        "assignerOrgId": "2e0a0ee2-d866-482a-9f5e-ac03d156dbaa",
        "state": "PUBLISHED",
        "assignerShortName": "Moxa",
        "dateReserved": "2025-02-25T08:08:57.582Z",
        "datePublished": "2025-10-23T13:56:39.744Z",
        "dateUpdated": "2025-10-23T14:35:30.379Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "TN-4500A Series",
                    "vendor": "Moxa",
                    "versions": [
                        {
                            "lessThanOrEqual": "3.13",
                            "status": "affected",
                            "version": "1.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "4.0",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "product": "TN-5500A Series",
                    "vendor": "Moxa",
                    "versions": [
                        {
                            "lessThanOrEqual": "3.13",
                            "status": "affected",
                            "version": "1.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "4.0",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "product": "TN-G4500 Series",
                    "vendor": "Moxa",
                    "versions": [
                        {
                            "lessThanOrEqual": "5.5",
                            "status": "affected",
                            "version": "1.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "5.5.255",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "product": "TN-G6500 Series",
                    "vendor": "Moxa",
                    "versions": [
                        {
                            "lessThanOrEqual": "5.5",
                            "status": "affected",
                            "version": "1.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "5.5.255",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "cpeMatch": [
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-4500a_series:*:*:*:*:*:*:*:*",
                                    "versionEndIncluding": "3.13",
                                    "versionStartIncluding": "1.0",
                                    "vulnerable": true
                                },
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-4500a_series:4.0:*:*:*:*:*:*:*",
                                    "vulnerable": false
                                }
                            ],
                            "negate": false,
                            "operator": "OR"
                        },
                        {
                            "cpeMatch": [
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-5500a_series:*:*:*:*:*:*:*:*",
                                    "versionEndIncluding": "3.13",
                                    "versionStartIncluding": "1.0",
                                    "vulnerable": true
                                },
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-5500a_series:4.0:*:*:*:*:*:*:*",
                                    "vulnerable": false
                                }
                            ],
                            "negate": false,
                            "operator": "OR"
                        },
                        {
                            "cpeMatch": [
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-g4500_series:*:*:*:*:*:*:*:*",
                                    "versionEndIncluding": "5.5",
                                    "versionStartIncluding": "1.0",
                                    "vulnerable": true
                                },
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-g4500_series:5.5.255:*:*:*:*:*:*:*",
                                    "vulnerable": false
                                }
                            ],
                            "negate": false,
                            "operator": "OR"
                        },
                        {
                            "cpeMatch": [
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-g6500_series:*:*:*:*:*:*:*:*",
                                    "versionEndIncluding": "5.5",
                                    "versionStartIncluding": "1.0",
                                    "vulnerable": true
                                },
                                {
                                    "criteria": "cpe:2.3:a:moxa:tn-g6500_series:5.5.255:*:*:*:*:*:*:*",
                                    "vulnerable": false
                                }
                            ],
                            "negate": false,
                            "operator": "OR"
                        }
                    ],
                    "operator": "OR"
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Aarón Flecha Menéndez"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Víctor Bello Cuevas"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This vulnerability is classified as Host Header Injection, where invalid Host headers can manipulate to redirect users, forge links, or phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of confidentiality, integrity, and availability within any subsequent systems.</span><br>"
                        }
                    ],
                    "value": "An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This vulnerability is classified as Host Header Injection, where invalid Host headers can manipulate to redirect users, forge links, or phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of confidentiality, integrity, and availability within any subsequent systems."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-154",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-154: Resource Location Spoofing"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "PRESENT",
                        "attackVector": "NETWORK",
                        "baseScore": 0,
                        "baseSeverity": "NONE",
                        "privilegesRequired": "LOW",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "userInteraction": "PASSIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "NONE",
                        "vulnConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "NONE",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-349",
                            "description": "CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "2e0a0ee2-d866-482a-9f5e-ac03d156dbaa",
                "shortName": "Moxa",
                "dateUpdated": "2025-10-23T13:56:39.744Z"
            },
            "references": [
                {
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-257421-cve-2025-1679,-cve-2025-1680-stored-cross-site-scripting-(xss)-and-host-header-injection-vulnerabilities-in"
                },
                {
                    "tags": [
                        "technical-description"
                    ],
                    "url": "https://www.hackrtu.com/blog/cg-technical-en-003/"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">Moxa has developed appropriate solutions to address these vulnerabilities. Please refer to&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://www.moxa.com/en/support/product-support/security-advisory/mpsa-257421-cve-2025-1679,-cve-2025-1680-stored-cross-site-scripting-(xss)-and-host-header-injection-vulnerabilities-in\">https://www.moxa.com/en/support/product-support/security-advisory/mpsa-257421-cve-2025-1679,-cve-202...</a></span><br>"
                        }
                    ],
                    "value": "Moxa has developed appropriate solutions to address these vulnerabilities. Please refer to  https://www.moxa.com/en/support/product-support/security-advisory/mpsa-257421-cve-2025-1679,-cve-202... https://www.moxa.com/en/support/product-support/security-advisory/mpsa-257421-cve-2025-1679,-cve-2025-1680-stored-cross-site-scripting-(xss)-and-host-header-injection-vulnerabilities-in"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 0.4.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-10-23T14:34:58.621334Z",
                                "id": "CVE-2025-1680",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-10-23T14:35:30.379Z"
                }
            }
        ]
    }
}