CVE Database
/

CVE-2026-25786

Back to search

CVE-2026-25786

Published: May 12, 2026

Modified: May 12, 2026

PUBLISHED

CVSS v3.1

9.1

CRITICAL

Description

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.

VendorProductVersions

Siemens

SIMATIC Drive Controller CPU 1504D TF

affected
0 - < V3.1.6

Siemens

SIMATIC Drive Controller CPU 1507D TF

affected
0 - < V3.1.6

Siemens

SIMATIC ET 200SP CPU 1510SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1510SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1510SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1512SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SP F-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SP-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SPT F-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SPT-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants)

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511C-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511T-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511T-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511TF-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511TF-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1512C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1512C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1512C-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513pro F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513pro-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515T-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515T-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515TF-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515TF-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516pro F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516pro-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516T-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516T-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1516TF-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516TF-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517F-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517F-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517F-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517T-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517T-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517TF-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517TF-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518F-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518F-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518T-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518T-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518TF-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518TF-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK

affected
0 - < *

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S F V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S F V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S F V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S F V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S F V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S F V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S T V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S TF V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller Linux V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller Linux V3

affected
0 - < *

Siemens

SIMATIC S7-PLCSIM Advanced

affected
0 - < *

Siemens

SIPLUS ET 200SP CPU 1510SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN TX RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN TX RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1518-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIPLUS S7-1500 CPU 1518F-4 PN/DP

affected
0 - < V3.1.6

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now