CVE Database
/

CVE-2026-25789

Back to search

CVE-2026-25789

Published: May 12, 2026

Modified: May 12, 2026

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file to be uploaded. This would result in malitcious JavaScript execution in the context of the authenticated user's session without requiring the file to be uploaded, potentially leading to session hijacking or credential theft.

VendorProductVersions

Siemens

SIMATIC Drive Controller CPU 1504D TF

affected
0 - < V3.1.6

Siemens

SIMATIC Drive Controller CPU 1507D TF

affected
0 - < V3.1.6

Siemens

SIMATIC ET 200SP CPU 1510SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1510SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1510SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC ET 200SP CPU 1512SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SP F-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SP-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SPT F-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1514SPT-2 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants)

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs

affected
0 - < *

Siemens

SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511C-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511T-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511T-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511TF-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1511TF-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1512C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1512C-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1512C-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513pro F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513pro-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515T-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515T-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515TF-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1515TF-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516pro F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516pro-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516T-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516T-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1516TF-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516TF-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517F-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517F-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517F-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517T-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517T-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1517TF-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1517TF-3 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518F-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518F-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518T-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518T-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU 1518TF-3 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1518TF-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK

affected
0 - < *

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN

affected
0 - < V2.9.9

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S F V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S F V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S F V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1507S V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S F V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S F V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S F V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S T V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S TF V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S V3

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller CPU 1508S V4

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller Linux V2

affected
0 - < *

Siemens

SIMATIC S7-1500 Software Controller Linux V3

affected
0 - < *

Siemens

SIMATIC S7-PLCSIM Advanced

affected
0 - < *

Siemens

SIPLUS ET 200SP CPU 1510SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1510SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS ET 200SP CPU 1512SP-1 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN TX RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511-1 PN TX RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1511F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1513F-1 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL

affected
0 - < V2.9.9

Siemens

SIPLUS S7-1500 CPU 1518-4 PN/DP

affected
0 - < V3.1.6

Siemens

SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

affected
0 - < V3.1.6

Siemens

SIPLUS S7-1500 CPU 1518F-4 PN/DP

affected
0 - < V3.1.6

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now