CVE-2025-9404: Scada-LTS

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /pointHierarchySLTS of the component Folder Handler. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Affected products

  • Scada-LTS Scada-LTS: up to and including 2.7.8.1

Published 2025-08-25. Last modified 2026-06-17.