Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27684 | Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device. |
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2025-011 |
|
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 May 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device. | |
| Title | PEPPERL+FUCHS: Profinet Gateway LB8122A.1.EL – Device is affected by XSS vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-05-27T14:18:17.838Z
Reserved: 2025-03-05T14:01:01.177Z
Link: CVE-2025-1985
Updated: 2025-05-27T14:18:12.648Z
Status : Deferred
Published: 2025-05-26T09:15:20.683
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-1985
No data.
OpenCVE Enrichment
No data.
EUVD