are susceptible to a cross-site scripting vulnerability, allowing
an attacker to craft a malicious payload in URL parameters, which would
execute in a client browser when accessed by a user, steal session
tokens, and control the service.
Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
Leviton has not responded to requests to work with CISA in mitigating this vulnerability. Users of these affected products are welcome to contact Leviton's customer support https://leviton.com/support/resources/product-support for additional information.
Fri, 18 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 17 Jul 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
Title | Leviton AcquiSuite and Energy Monitoring Hub Cross-site Scripting | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-07-18T13:55:42.662Z
Reserved: 2025-06-16T19:42:27.690Z
Link: CVE-2025-6185

Updated: 2025-07-18T13:55:39.761Z

Status : Awaiting Analysis
Published: 2025-07-18T00:15:24.463
Modified: 2025-07-22T13:06:27.983
Link: CVE-2025-6185

No data.

No data.