CVE-2026-25786
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.5% (43º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Il punto debole qui non è la logica di controllo. È il web server SIMATIC S7, quindi l’esposizione si trova nell’interfaccia di gestione che gli operatori usano per amministrare i PLC, e alcuni modelli interessati non hanno ancora una versione di correzione disponibile.
1 fonte · 14 mag
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.5% (43º percentile).
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. EPSS 0.5% (43º percentile).
CVSS 7.1 HIGH: affected devices do not properly validate and sanitize filenames on the Firmware Update page. EPSS 0.5% (38º percentile).
CISA Advisories
Siemens SIMATIC S7 PLC Web Server | CISA
Siemens SIMATIC S7 PLC Web Server Summary SIMATIC S7 PLCs contain multiple vulnerabilities in the web server that could allow an attacker to perform cross-site scripting attacks.
originalePart of the PlainSec briefing for 2026-05-14
Every edition of this story: Alcune interfacce web PLC Siemens sono ancora prive di correzioni