Improper Neutralization in B&R Automation Runtime's System Diagnostics Manager
CVE-2025-11498
5.3MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-11498?
A flaw in the System Diagnostics Manager of B&R Automation Runtime allows an attacker to craft a malicious link that, when clicked by a user, results in a CSV file that can have injected formula data. To exploit this vulnerability, the user must open the resultant CSV file manually, potentially leading to unauthorized actions or data manipulation.
Affected Version(s)
Automation Runtime 6.0 < 6.4
Automation Runtime 4