CVE-2019-25244: Bticino S.p.a Legrand Bticino Driver Manager f454
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unvalidated GET parameters.
Affected products
- Bticino S.p.a Legrand Bticino Driver Manager f454: version 1.0.51 only; version 1.1.14 only
Published 2025-12-24. Last modified 2026-06-17.