CVE-2026-25789
Last modified
CVE-2026-25789 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file to be uploaded. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file to be uploaded. This would result in malitcious JavaScript execution in the context of the authenticated user's session without requiring the file to be uploaded, potentially leading to session hijacking or credential theft.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SIMATIC Drive Controller CPU 1504D TF | < V3.1.6 |
| Siemens | SIMATIC Drive Controller CPU 1507D TF | < V3.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1510SP F-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1510SP F-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1510SP F-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1510SP-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1510SP-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1510SP-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1512SP F-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1512SP F-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1512SP F-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1512SP-1 PN | < * |
| Siemens | SIMATIC ET 200SP CPU 1512SP-1 PN | < V2.9.9 |
| Siemens | SIMATIC ET 200SP CPU 1512SP-1 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SP F-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SP-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SPT F-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP CPU 1514SPT-2 PN | < V4.1.6 |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) | < * |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs | < * |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs | < * |
| Siemens | SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs | < * |
| Siemens | SIMATIC S7-1500 CPU 1511-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1511-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511C-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511C-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511F-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1511F-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511F-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511T-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511T-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1511TF-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1511TF-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1512C-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1512C-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1513-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1513-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513F-1 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1513F-1 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1513F-1 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513pro F-2 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1513pro-2 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1515-2 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1515-2 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1515-2 PN | < V4.1.6 |
| Siemens | SIMATIC S7-1500 CPU 1515F-2 PN | < * |
| Siemens | SIMATIC S7-1500 CPU 1515F-2 PN | < V2.9.9 |
| Siemens | SIMATIC S7-1500 CPU 1515F-2 PN | < V4.1.6 |
Showing 50 of 139 affected configurations. See the CNA advisory for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-25789?
How severe is CVE-2026-25789?
How do I fix CVE-2026-25789?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25781in OpenHarmony v6.0 and prior versions allow a local attacke…8.4
- CVE-2026-25782Gitea versions before 1.25.5 look up tracked-time entries by…5.3
- CVE-2026-25783Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.1…4.3
- CVE-2026-25785Path traversal vulnerability exists in Lanscope Endpoint Man…9.8
- CVE-2026-25786Affected devices do not properly validate and sanitize PLC/s…9.3
- CVE-2026-25787Affected devices do not properly validate and sanitize Techn…9.3
- CVE-2026-2579The WowStore – Store Builder & Product Blocks for WooCommerc…7.5
- CVE-2026-25790Wazuh is a free and open source platform used for threat pre…7.2
- CVE-2026-25791Sliver is a command and control framework that uses a custom…7.5
- CVE-2026-25792Greenshot is an open source Windows screenshot utility. Vers…6.5
- CVE-2026-25793Nebula is a scalable overlay networking tool. In versions fr…8.1
- CVE-2026-25794ImageMagick is free and open-source software used for editin…8.2
Are you affected by CVE-2026-25789?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
