Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Hard-coded JWT Signing Key Authentication Bypass in Moxa Network Security Appliances and Routers

IdentifiersCVE-2025-6950CWE-798· Use of Hard-coded Credentials

CVE-2025-6950 is a critical use of hard-coded credentials vulnerability in Moxa network security appliances and routers. The affected devices use a hard-coded secret key to sign JSON Web Tokens (JWTs) used for authentication. Because the signing key is embedded and not unique or securely managed, an unauthenticated remote attacker can generate forged JWTs that are accepted as valid by the device. This allows authentication bypass and impersonation of arbitrary users, including administrative users. The issue affects Moxa product lines reported as versions prior to v3.21, including EDF-G1002-BP, EDR-8010, EDR-G9010, NAT-102, NAT-108, TN-4900, and OnCell G4302-LTE4. The vulnerability is rated CVSS v4.0 9.9 (Critical) and can lead to complete compromise of the affected device.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated attacker to bypass authentication entirely, impersonate any user, and obtain full administrative control of the affected device. This can result in unauthorized access to device functions and data, theft of sensitive information stored or processed on the device, modification of configuration, and complete compromise of the device’s confidentiality, integrity, and availability. The provided sources state the impact is severe on the affected device itself, while not indicating loss of confidentiality or integrity in subsequent systems.

Mitigation

If you can’t patch tonight, do this now.

Until patches can be applied, restrict network exposure of affected devices to trusted management networks only, disable or tightly control remote administrative access where operationally possible, and increase monitoring for anomalous authentication events, unexpected administrative actions, forged or unusual JWT usage, configuration changes, and new accounts. Review logs for signs of prior compromise and be prepared to rotate credentials and re-establish trust after remediation. Where feasible, segment affected devices from broader IT/OT environments to reduce blast radius. The content also recommends secure JWT practices generally, including eliminating hard-coded signing secrets and using properly managed signing keys.

Remediation

Patch, then assume compromise.

Apply the latest Moxa firmware updates referenced in security advisory MPSA-258121 with highest priority after appropriate testing and validation. For affected OnCell G4302-LTE4 devices, Moxa indicates customers should contact technical support to obtain the fix. Remediation guidance in the provided content also includes removing the hard-coded credential condition, implementing secure JWT signing, and re-authenticating all users after update. Because exploitation enables full device compromise, treat vulnerable devices as potentially compromised prior to patching and investigate for unauthorized access or persistence rather than assuming patching alone is sufficient.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
MoxaEdf-G1002-Bp Serieshardware
MoxaEdr-8010 Seriesapplication
MoxaEdr-G9010 Seriesapplication
MoxaNat-102 Serieshardware
MoxaNat-108 Serieshardware
MoxaOncell G4302-Lte4 Serieshardware
MoxaTn-4900 Serieshardware

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.