Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-0193— Stored Cross-site Scripting (XSS) Vulnerability in the MGate 5121/5122/5123 Series

EPSS 0.21% · P43
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-0193

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stored Cross-site Scripting (XSS) Vulnerability in the MGate 5121/5122/5123 Series
Source: NVD (National Vulnerability Database)
Vulnerability Description
A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
MOXA多款产品 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MOXA MGate 5121等都是中国摩莎(MOXA)公司的一款工业以太网网关。 MOXA多款产品存在跨站脚本漏洞,该漏洞源于对用户输入的清理和编码不足,容易受到存储型跨站脚本攻击。以下产品及版本受到影响:MGate 5121、MGate 5122和MGate 5123 v1.0版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MoxaMGate 5121 Series 1.0 -
MoxaMGate 5122 Series 1.0 -
MoxaMGate 5123 Series 1.0 -

II. Public POCs for CVE-2025-0193

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-0193

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-0193

No comments yet


Leave a comment