CVE-2026-25786

CRITICALCVSS 9.3/10EPSS 0.37%

Last modified

CVE-2026-25786 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.

Description

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.

Metrics

CVSS 3.1
9.1/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVSS 4.0
9.3/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.37%

29.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
SiemensSIMATIC Drive Controller CPU 1504D TF< V3.1.6
SiemensSIMATIC Drive Controller CPU 1507D TF< V3.1.6
SiemensSIMATIC ET 200SP CPU 1510SP F-1 PN< *
SiemensSIMATIC ET 200SP CPU 1510SP F-1 PN< V2.9.9
SiemensSIMATIC ET 200SP CPU 1510SP F-1 PN< V4.1.6
SiemensSIMATIC ET 200SP CPU 1510SP-1 PN< *
SiemensSIMATIC ET 200SP CPU 1510SP-1 PN< V2.9.9
SiemensSIMATIC ET 200SP CPU 1510SP-1 PN< V4.1.6
SiemensSIMATIC ET 200SP CPU 1512SP F-1 PN< *
SiemensSIMATIC ET 200SP CPU 1512SP F-1 PN< V2.9.9
SiemensSIMATIC ET 200SP CPU 1512SP F-1 PN< V4.1.6
SiemensSIMATIC ET 200SP CPU 1512SP-1 PN< *
SiemensSIMATIC ET 200SP CPU 1512SP-1 PN< V2.9.9
SiemensSIMATIC ET 200SP CPU 1512SP-1 PN< V4.1.6
SiemensSIMATIC ET 200SP CPU 1514SP F-2 PN< V4.1.6
SiemensSIMATIC ET 200SP CPU 1514SP-2 PN< V4.1.6
SiemensSIMATIC ET 200SP CPU 1514SPT F-2 PN< V4.1.6
SiemensSIMATIC ET 200SP CPU 1514SPT-2 PN< V4.1.6
SiemensSIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants)< *
SiemensSIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs< *
SiemensSIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs< *
SiemensSIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs< *
SiemensSIMATIC S7-1500 CPU 1511-1 PN< *
SiemensSIMATIC S7-1500 CPU 1511-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1511-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1511C-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1511C-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1511F-1 PN< *
SiemensSIMATIC S7-1500 CPU 1511F-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1511F-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1511T-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1511T-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1511TF-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1511TF-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1512C-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1512C-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1513-1 PN< *
SiemensSIMATIC S7-1500 CPU 1513-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1513-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1513F-1 PN< *
SiemensSIMATIC S7-1500 CPU 1513F-1 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1513F-1 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1513pro F-2 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1513pro-2 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1515-2 PN< *
SiemensSIMATIC S7-1500 CPU 1515-2 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1515-2 PN< V4.1.6
SiemensSIMATIC S7-1500 CPU 1515F-2 PN< *
SiemensSIMATIC S7-1500 CPU 1515F-2 PN< V2.9.9
SiemensSIMATIC S7-1500 CPU 1515F-2 PN< V4.1.6

Showing 50 of 139 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-25786?
Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.
How severe is CVE-2026-25786?
CVE-2026-25786 has a CVSS score of 9.3/10 (CRITICAL severity). The EPSS model estimates a 0.37% probability of exploitation in the next 30 days.
How do I fix CVE-2026-25786?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-25786?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST