CVE-2018-25090
Wago: Improper Neutralization of Input During Web Page Generation in multiple devices
An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected products
WAGO · Controller BACnet/IPWAGO · Controller BACnet MS/TPWAGO · Ethernet Controller 3rd GenerationWAGO · Fieldbus Coupler Ethernet 3rd GenerationWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →