PT-2025-25539 · Wago+1 · Cc100 0751-9X01+16

Published

2025-06-13

·

Updated

2025-11-21

·

CVE-2025-25264

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-06879
CVE-2025-25264

Affected Products

Cc100 0751-9X01
Edge Controller 0752-8303/8000-0002
Pfc100 G1 0750-810X
Pfc100 G1 0750-810X/Xxxx-Xxxx
Pfc100 G2 0750-811X
Pfc100 G2 0750-811X-Xxxx-Xxxx
Pfc200 G1 750-820X
Pfc200 G1 750-820X-Xxx-Xxx
Pfc200 G2 750-821
Pfc200 G2 750-821X-Xxx-Xxx
Tp600 0762-420X/8000-000X
Tp600 0762-430X/8000-000X
Tp600 0762-520X/8000-000X
Tp600 0762-530X/8000-000X
Tp600 0762-620X/8000-000X
Tp600 0762-630X/8000-000X
Compact Controller Cc100