PT-2026-1672 · Leica Geosystems · Leica Geosystems Gr10+3
Published
2026-01-07
·
Updated
2026-01-08
·
CVE-2019-25259
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Leica Geosystems GR10/GR25/GR30/GR50 GNSS version 4.30.063
Description
The software contains a cross-site request forgery issue that could allow attackers to perform administrative actions without proper validation of requests. Attackers can potentially trick authenticated users into unintentionally executing unauthorized actions through malicious web pages that submit requests to the application.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Leica Geosystems Gr10
Leica Geosystems Gr25
Leica Geosystems Gr30
Leica Geosystems Gr50