Stored Cross-Site Scripting Flaw in Leica Geosystems GNSS Products
CVE-2018-25131
Key Information:
- Vendor
Leica Geosystems Ag
- Status
- Vendor
- CVE Published:
- 24 December 2025
Badges
What is CVE-2018-25131?
Leica Geosystems' GNSS products, specifically versions GR10, GR25, GR30, and GR50 running 4.30.063, are vulnerable to a stored cross-site scripting attack through their configuration file upload feature. This vulnerability allows attackers to upload a malicious HTML file, resulting in arbitrary JavaScript being executed within an unsuspecting user's browser session when they access the compromised file. This can lead to unauthorized actions on behalf of the user, compromising sensitive information or sessions.
Affected Version(s)
GR10/GR25/GR30/GR50 GNSS 4.30.063
GR10/GR25/GR30/GR50 GNSS 4.20.232
GR10/GR25/GR30/GR50 GNSS 4.11.606
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
