CVE-2019-25259: Leica Geosystems AG Leica Geosystems GR10/GR25/GR30/GR50 Gnss
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can trick logged-in users into executing unauthorized actions by crafting malicious web pages that submit requests to the application.
Affected products
- Leica Geosystems AG Leica Geosystems GR10/GR25/GR30/GR50 Gnss: version 4.30.063 only; version 4.20.232 only; version 4.11.606 only; version 3.22.1818 only; version 3.10.1633 only; version 2.62.782 only; …
Published 2026-01-08. Last modified 2026-06-17.