CVE-2015-6466: Moxa Eds-405a Firmware

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web script or HTML via an unspecified field.

Affected products

  • Moxa Eds-405a Firmware: up to and including 3.4
  • Moxa Eds-408a Firmware: up to and including 3.4

Published 2015-09-11. Last modified 2026-06-17.