CVE-2025-6185: CWE-79 in Leviton AcquiSuite
Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.
CVE-2025-6185: CWE-79 in Leviton AcquiSuite
Description
Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- icscert
- Date Reserved
- 2025-06-16T19:42:27.690Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 687a572ba83201eaacf43288
Added to database: 7/18/2025, 2:16:11 PM
Last updated: 7/18/2025, 2:16:11 PM
Views: 1
Related Threats
CVE-2025-46002: n/a
UnknownCVE-2025-7784: Improper Privilege Management in Red Hat Red Hat Build of Keycloak
MediumCVE-2025-46001: n/a
CriticalCVE-2025-7786: Cross Site Scripting in Gnuboard g6
MediumCVE-2025-7785: Open Redirect in thinkgem JeeSite
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.