CVE-2025-5191 - CVE House
Back to Database
Status published High CVE-2025-5191

Unquoted Search Path Vulnerability in the Utility for Industrial Computers (Windows)

Vulnerability Description

An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in a higher-priority directory within the search path. When the Serial Interface service starts, the malicious executable could be run with SYSTEM privileges. Successful exploitation could allow privilege escalation or enable an attacker to maintain persistence on the affected system. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality, integrity, or availability within any subsequent systems.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5191

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Anni Tuulinen

Affected Vendor

Affected Software

Utility for DRP-A100 Series, Utility for DRP-C100 Series
Vulnerable Versions:
1.0, 1.2, 1.1

Timeline

Official Publish: August 25th, 2025
Last Modified: August 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)