CVE-2026-25787
Last modified
CVE-2026-25787 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "Motion Control Diagnostics" parameters page, the malicious code would be executed in the scope of their web session.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "Motion Control Diagnostics" parameters page, the malicious code would be executed in the scope of their web session.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SIMATIC Drive Controller CPU 1504D TF | < V3.1.6 |
| Siemens | SIMATIC Drive Controller CPU 1507D TF | < V3.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1510SP F-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1510SP F-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1510SP F-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1510SP-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1510SP-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1510SP-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1512SP F-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1512SP F-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1512SP F-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1512SP-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1512SP-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1512SP-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SP F-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SP-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SPT F-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SPT-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) | < * |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs | < * |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs | < * |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs | < * |
| Siemens | SIMATIC S7-1500 CPU 1511-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1511-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511C-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511C-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511F-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1511F-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511F-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511T-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511T-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511TF-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511TF-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1512C-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1512C-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1513-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1513-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513F-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1513F-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1513F-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513pro F-2 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513pro-2 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1515-2 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1515-2 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1515-2 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1515F-2 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1515F-2 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1515F-2 PN | < V4.1.6 |
Showing 50 of 139 affected configurations. See the CNA advisory for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-25787?
How severe is CVE-2026-25787?
How do I fix CVE-2026-25787?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25780Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.1…4.3
- CVE-2026-25781in OpenHarmony v6.0 and prior versions allow a local attacke…8.4
- CVE-2026-25782Gitea versions before 1.25.5 look up tracked-time entries by…5.3
- CVE-2026-25783Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.1…4.3
- CVE-2026-25785Path traversal vulnerability exists in Lanscope Endpoint Man…9.8
- CVE-2026-25786Affected devices do not properly validate and sanitize PLC/s…9.3
- CVE-2026-25789Affected devices do not properly validate and sanitize filen…7.2
- CVE-2026-2579The WowStore – Store Builder & Product Blocks for WooCommerc…7.5
- CVE-2026-25790Wazuh is a free and open source platform used for threat pre…7.2
- CVE-2026-25791Sliver is a command and control framework that uses a custom…7.5
- CVE-2026-25792Greenshot is an open source Windows screenshot utility. Vers…6.5
- CVE-2026-25793Nebula is a scalable overlay networking tool. In versions fr…8.1
Are you affected by CVE-2026-25787?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
