CVE-2018-25131: Leica Geosystems AG GR10/GR25/GR30/GR50 Gnss
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configuration file upload functionality. Attackers can upload a malicious HTML file to that executes arbitrary JavaScript in a user's browser session when viewed.
Affected products
- Leica Geosystems AG GR10/GR25/GR30/GR50 Gnss: version 4.30.063 only; version 4.20.232 only; version 4.11.606 only; version 3.22.1818 only; version 3.10.1633 only; version 2.62.782 only; …
Published 2025-12-24. Last modified 2026-06-17.