are susceptible to a cross-site scripting vulnerability, allowing
an attacker to craft a malicious payload in URL parameters, which would
execute in a client browser when accessed by a user, steal session
tokens, and control the service.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Leviton has not responded to requests to work with CISA in mitigating this vulnerability. Users of these affected products are welcome to contact Leviton's customer support https://leviton.com/support/resources/product-support for additional information.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21832 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. |
Fri, 18 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
| Title | Leviton AcquiSuite and Energy Monitoring Hub Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-07-18T13:55:42.662Z
Reserved: 2025-06-16T19:42:27.690Z
Link: CVE-2025-6185
Updated: 2025-07-18T13:55:39.761Z
Status : Deferred
Published: 2025-07-18T00:15:24.463
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-6185
No data.
OpenCVE Enrichment
No data.
EUVD