CVE-2025-6949
published 2025-10-17CVE-2025-6949: An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in…
PriorityP264critical9.3CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.49%
39.3th percentile
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In certain scenarios, this vulnerability could allow an attacker to gain full administrative control over the affected device, leading to potential account impersonation. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 6.11.0 < 6.12.56 | 6.12.56 |
| linux | linux_kernel | >= 6.13.0 < 6.17.6 | 6.17.6 |
| moxa | edf-g1002-bp_series | 1.0 – 3.17 | — |
| moxa | edr-8010_series | 1.0 – 3.17 | — |
| moxa | edr-g9010_series | 1.0 – 3.14 | — |
| moxa | nat-102_series | 1.0 – 3.17 | — |
| moxa | nat-108_series | 1.0 – 3.16 | — |
| moxa | oncell_g4302-lte4_series | 1.0 – 3.13 | — |
| moxa | tn-4900_series | 1.0 – 3.14 | — |
CVSS provenance
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
net/smc: fix general protection fault in __smc_diag_dump
osv·2025-12-16
CVE-2025-40357 net/smc: fix general protection fault in __smc_diag_dump
net/smc: fix general protection fault in __smc_diag_dump
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix general protection fault in __smc_diag_dump
The syzbot report a crash:
Oops: general protection fault, probably for non-canonical address 0xfbd5a5d5a0000003: 0000 [#1] SMP KASAN NOPTI
KASAN: maybe wild-memory-access in range [0xdead4ead00000018-0xdead4ead0000001f]
CPU: 1 UID: 0 PID: 6949 Comm: syz.0.335 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025
RIP: 0010:smc_diag_msg_common_fill net/smc/smc_diag.c:44 [inline]
RIP: 0010:__smc_diag_dump.constprop.0+0x3ca/0x2550 net/smc/smc_diag.c:89
Call Trace:
smc_diag_dump_proto+0x26d/0x420 net/smc/smc_diag.c:217
smc_diag_dump+0x27/0x90
GHSA
GHSA-xqwv-wj6g-m73m: An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers
ghsa_unreviewed·2025-10-17
CVE-2025-6949 [CRITICAL] CWE-250 GHSA-xqwv-wj6g-m73m: An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In certain scenarios, this vulnerability could allow an attacker to gain full administrative control over the affected device, leading to potential account impersonation. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality or integrity within any subsequent systems.
Red Hat
kernel: net/smc: fix general protection fault in __smc_diag_dump
vendor_redhat·2025-12-16·CVSS 5.5
CVE-2025-40357 [LOW] kernel: net/smc: fix general protection fault in __smc_diag_dump
kernel: net/smc: fix general protection fault in __smc_diag_dump
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix general protection fault in __smc_diag_dump
The syzbot report a crash:
Oops: general protection fault, probably for non-canonical address 0xfbd5a5d5a0000003: 0000 [#1] SMP KASAN NOPTI
KASAN: maybe wild-memory-access in range [0xdead4ead00000018-0xdead4ead0000001f]
CPU: 1 UID: 0 PID: 6949 Comm: syz.0.335 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025
RIP: 0010:smc_diag_msg_common_fill net/smc/smc_diag.c:44 [inline]
RIP: 0010:__smc_diag_dump.constprop.0+0x3ca/0x2550 net/smc/smc_diag.c:89
Call Trace:
smc_diag_dump_proto+0x26d/0x420 net/smc/smc_diag.c:217
smc_diag_dump+0x27/
No detection rules found.
No public exploits indexed.
2025-10-17
Published