Improper Validation in Siemens PLC Web Interface
CVE-2026-25786
9.3CRITICAL
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-25786?
The Siemens PLC Web Interface is susceptible to improper validation and sanitization of the PLC/station name found on the 'communication' parameters page. This vulnerability allows an authenticated attacker, who can download a TIA project into the product, to inject harmful scripts. When a legitimate user with appropriate permissions accesses the 'communication' parameters page, the injected malicious code may execute within their web session, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
SIMATIC Drive Controller CPU 1504D TF 0
SIMATIC Drive Controller CPU 1507D TF 0
SIMATIC ET 200SP CPU 1510SP F-1 PN 0