CVE-2018-25090: Wago Controller Bacnet/ip
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability.
Affected products
- Wago Controller Bacnet/ip
- Wago Controller Bacnet Ms/tp
- Wago Ethernet Controller 3rd Generation
- Wago Fieldbus Coupler Ethernet 3rd Generation
Published 2024-03-13. Last modified 2026-06-17.