PT-2026-1672 · Leica Geosystems · Leica Geosystems Gr10+3

Published

2026-01-07

·

Updated

2026-01-08

·

CVE-2019-25259

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Leica Geosystems GR10/GR25/GR30/GR50 GNSS version 4.30.063
Description The software contains a cross-site request forgery issue that could allow attackers to perform administrative actions without proper validation of requests. Attackers can potentially trick authenticated users into unintentionally executing unauthorized actions through malicious web pages that submit requests to the application.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-25259

Affected Products

Leica Geosystems Gr10
Leica Geosystems Gr25
Leica Geosystems Gr30
Leica Geosystems Gr50