CVE-2025-1985: Pepperl+fuchs Profinet Gateway FB8122A.1.EL

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.

Affected products

  • Pepperl+fuchs Profinet Gateway FB8122A.1.EL: before V1.3.13 (fixed in V1.3.13)
  • Pepperl+fuchs Profinet Gateway LB8122A.1.EL: before V1.3.13 (fixed in V1.3.13)

Published 2025-05-26. Last modified 2026-06-17.