CVE-2025-13902
EUVD-2025-20850010.03.2026, 18:17
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| schneider-electric | modicon_m258_firmware | - |
| schneider-electric | modicon_lmc058_firmware | - |
| schneider-electric | modicon_m251_firmware | 𝑥 < 5.4.13.12 |
| schneider-electric | modicon_m241_firmware | 𝑥 < 5.4.13.12 |
𝑥
= Vulnerable software versions