are susceptible to a cross-site scripting vulnerability, allowing
an attacker to craft a malicious payload in URL parameters, which would
execute in a client browser when accessed by a user, steal session
tokens, and control the service.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21832 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. |
Solution
No solution given by the vendor.
Workaround
Leviton has not responded to requests to work with CISA in mitigating this vulnerability. Users of these affected products are welcome to contact Leviton's customer support https://leviton.com/support/resources/product-support for additional information.
Fri, 18 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
| Title | Leviton AcquiSuite and Energy Monitoring Hub Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-07-18T13:55:42.662Z
Reserved: 2025-06-16T19:42:27.690Z
Link: CVE-2025-6185
Updated: 2025-07-18T13:55:39.761Z
Status : Awaiting Analysis
Published: 2025-07-18T00:15:24.463
Modified: 2025-07-22T13:06:27.983
Link: CVE-2025-6185
No data.
OpenCVE Enrichment
No data.
EUVD