9.3
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Description
Leviton AcquiSuite and Energy Monitoring Hub
are susceptible to a cross-site scripting vulnerability, allowing
an attacker to craft a malicious payload in URL parameters, which would
execute in a client browser when accessed by a user, steal session
tokens, and control the service.
are susceptible to a cross-site scripting vulnerability, allowing
an attacker to craft a malicious payload in URL parameters, which would
execute in a client browser when accessed by a user, steal session
tokens, and control the service.
Basic Information
ID
CVE-2025-6185
Source
icscert
Published
Jul 17, 2025 at 23:14
Modified
Jul 18, 2025 at 13:55
Affected Product
Vendor
Leviton
Product
AcquiSuite
Version
Version A8810
Affected Versions
Leviton AcquiSuite Version A8810
Leviton Energy Monitoring Hub Version A8812
Leviton Energy Monitoring Hub Version A8812