CVE-2025-13902
published 2026-03-10CVE-2025-13902: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.22%
13.0th percentile
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | modicon_m241_firmware | < 5.4.13.12 | 5.4.13.12 |
| schneider-electric | modicon_m251_firmware | < 5.4.13.12 | 5.4.13.12 |
| schneider_electric | modicon_controllers_m241_m251 | — | — |
| schneider_electric | modicon_controllers_m258_lmc058 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Modicon Controllers M241, M251, M258, and LMC058
cisa_ics·2026-03-19·CVSS 5.1
[MEDIUM] Schneider Electric Modicon Controllers M241, M251, M258, and LMC058
ICS Advisory
##
Schneider Electric Modicon Controllers M241, M251, M258, and LMC058
Release DateMarch 19, 2026
Alert CodeICSA-26-078-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of this vulnerability may risk a Cross-site Scripting or an open redirect attack which could result in an account takeover scenario or the execution of code in the user browser.
The following versions of Schneider Electric Modicon Controllers M241, M251, M258, and LMC058 are affected:
- Modicon M241 versions prior to 5.4.13.12 Modicon_Controller_M241
- Modicon M251 versions prior to 5.4.13.12 Modicon_Controller_M251
- Modicon Controllers M258 all firmware versions Modicon_Controllers_M258
- M
GHSA
GHSA-pm47-v83p-5qpg: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where auth
ghsa_unreviewed·2026-03-10
CVE-2025-13902 [MEDIUM] CWE-79 GHSA-pm47-v83p-5qpg: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where auth
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-10
Published