LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-25787

Published
CVSS9.1
Severitycritical
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "Motion Control Diagnostics" parameters page, the malicious code would be executed in the scope of their web session.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-25787

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-25787.